[security][CVE-2026-73646] postcss in web toolchain #162
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
New active high-severity CVE detected by the
cve-security-triageautomation.postcss8.5.15via root override inpackage.json/bun.lock, mirrored indeployment/docker/workspace-root/package.json/bun.lock8.5.18Project impact
This repo ships the vulnerable PostCSS version in the web build toolchain used by Next.js and the Docker workspace sync. The published advisory says vulnerable PostCSS can read attacker-chosen source map paths when processing untrusted CSS with source maps enabled, which can disclose
sourcesContentfrom reachable.mapfiles. I have not verified a live exploit path in Islandflow, but the dependency is active and unpatched in the build/deploy surface.Recommended remediation
postcssoverride from8.5.15to8.5.18or laterbun.lockanddeployment/docker/workspace-root/bun.lockRun counters
Sources