PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
- Severity:
- High
Description
File: lib/previous-map.js Line: 87-98 (loadFile), 129-144 (loadMap)
Recommendation
Update the postcss package to the latest compatible version. Followings are version details:
- Affected version(s): <= 8.5.17
- Patched version(s): 8.5.18
References
Related Issues
- PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments - CVE-2026-45623
- PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `f - CVE-2026-69153
- Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read - CVE-2026-40163
- @tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files - CVE-2026-33949
You might also like:
- Tags:
- npm
- postcss
Anything's wrong? Let us know Last updated on August 13, 2026


