PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.
CVSS Details
- CVSS 4.0 Base Score: 6.3 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade aap-metrics-utilityUpgrade automation-platform-uiUpgrade python3.12-django-ansible-base+channel_authUpgrade flightctl-observabilityUpgrade receptor-debugsourceUpgrade python3.12-django-ansible-base+oauth2_providerUpgrade automation-controllerUpgrade python3.12-django-ansible-base+feature_flagsUpgrade automation-gateway-configUpgrade automation-eda-controller-baseUpgrade automation-gateway-proxy-debugsourceUpgrade flightctl-agentUpgrade python3.12-django-ansible-base+jwt_consumerUpgrade python3.12-django-ansible-base+authenticationUpgrade python3.12-django-ansible-baseUpgrade automation-gateway-proxy-serverUpgrade automation-eda-controller-worker-servicesUpgrade automation-gateway-proxy-server-debuginfoUpgrade flightctl-servicesUpgrade python3.12-galaxy-ngUpgrade rh-podman-desktopUpgrade automation-gateway-serverUpgrade automation-eda-controllerUpgrade python3.12-django-ansible-base+api_documentationUpgrade python3.12-django-ansible-base+activitystreamUpgrade automation-gatewayUpgrade automation-controller-serverUpgrade python3.12-sqlparseUpgrade python3.12-gitpythonUpgrade automation-eda-controller-base-servicesUpgrade automation-gateway-proxyUpgrade automation-controller-uiUpgrade python3.12-django-ansible-base+resource_registryUpgrade automation-eda-controller-event-stream-servicesUpgrade python3.12-django-ansible-base+rbacUpgrade flightctl-cliUpgrade flightctl-selinuxUpgrade receptorctlUpgrade receptor-debuginfoUpgrade automation-controller-cliUpgrade automation-hubUpgrade python3-sqlparseUpgrade automation-controller-venv-towerUpgrade receptorUpgrade python3.12-django-ansible-base+redis_clientUpgrade python3.12-django-ansible-base+rest_filters | Aug 5, 2026 | Aug 3, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub