[security][CVE-2026-73646] postcss in web toolchain #162

Open
opened 2026-08-22 13:17:51 +00:00 by dirtydishes · 0 comments
Owner

New active high-severity CVE detected by the cve-security-triage automation.

  • CVE: CVE-2026-73646
  • Component: postcss
  • In-repo version: 8.5.15 via root override in package.json / bun.lock, mirrored in deployment/docker/workspace-root/package.json / bun.lock
  • Severity: High (CVSS 7.5)
  • Fixed version: 8.5.18
  • Published: 2026-08-17

Project impact

This repo ships the vulnerable PostCSS version in the web build toolchain used by Next.js and the Docker workspace sync. The published advisory says vulnerable PostCSS can read attacker-chosen source map paths when processing untrusted CSS with source maps enabled, which can disclose sourcesContent from reachable .map files. I have not verified a live exploit path in Islandflow, but the dependency is active and unpatched in the build/deploy surface.

Recommended remediation

  • Bump the root postcss override from 8.5.15 to 8.5.18 or later
  • Regenerate bun.lock and deployment/docker/workspace-root/bun.lock
  • Re-run the CVE scan to confirm the finding clears

Run counters

  • unaddressed critical CVEs: 6
  • unaddressed medium/low CVEs: 170
  • unaddressed total CVEs: 240

Sources

New active high-severity CVE detected by the `cve-security-triage` automation. - CVE: CVE-2026-73646 - Component: `postcss` - In-repo version: `8.5.15` via root override in `package.json` / `bun.lock`, mirrored in `deployment/docker/workspace-root/package.json` / `bun.lock` - Severity: High (CVSS 7.5) - Fixed version: `8.5.18` - Published: 2026-08-17 Project impact This repo ships the vulnerable PostCSS version in the web build toolchain used by Next.js and the Docker workspace sync. The published advisory says vulnerable PostCSS can read attacker-chosen source map paths when processing untrusted CSS with source maps enabled, which can disclose `sourcesContent` from reachable `.map` files. I have not verified a live exploit path in Islandflow, but the dependency is active and unpatched in the build/deploy surface. Recommended remediation - Bump the root `postcss` override from `8.5.15` to `8.5.18` or later - Regenerate `bun.lock` and `deployment/docker/workspace-root/bun.lock` - Re-run the CVE scan to confirm the finding clears Run counters - unaddressed critical CVEs: 6 - unaddressed medium/low CVEs: 170 - unaddressed total CVEs: 240 Sources - https://github.com/advisories/GHSA-r28c-9q8g-f849 - https://www.cve.org/CVERecord?id=CVE-2026-73646 - https://github.com/postcss/postcss/releases/tag/8.5.18
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#162
No description provided.