Vulnerability in postcss
Severity: high
CVE: No CVE listed
Vulnerable range: <=8.5.22
Advisory: GHSA-fxqj-rqcc-2cmp; GHSA-r28c-9q8g-f849
Description: PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when from is unset; PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
Fix recommendation
Run npm audit fix to resolve this vulnerability.
Affected paths
Automatically detected by dependency vulnerability scan.
Vulnerability in
postcssSeverity: high
CVE: No CVE listed
Vulnerable range: <=8.5.22
Advisory: GHSA-fxqj-rqcc-2cmp; GHSA-r28c-9q8g-f849
Description: PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when
fromis unset; PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File DisclosureFix recommendation
Run
npm audit fixto resolve this vulnerability.Affected paths
Automatically detected by dependency vulnerability scan.