Skip to content

chore: upgrade postcss to ^8.5.25 to address CVE-2026-69153 - #1543

Merged
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/postcss-8.5.25
Aug 5, 2026
Merged

chore: upgrade postcss to ^8.5.25 to address CVE-2026-69153#1543
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/postcss-8.5.25

Conversation

@claude

@claude claude Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1815

Refreshes the postcss lockfile entry from 8.5.22 to 8.5.25, which addresses:

  • CVE-2026-69153 (GHSA-fxqj-rqcc-2cmp, MEDIUM) — information disclosure via a crafted sourceMappingURL. When from is unset, an attacker can make PreviousMap.loadFile() read an unintended source-map file through an absolute or directory-traversal sourceMappingURL, exposing the map's sources and sourcesContent to the application. Patched in 8.5.19; the advisory floor tracked in the issue is 8.5.23.

Every requester (@sourcebot/web via ^8.5.12, next@16.2.11 via ^8.5.12, tailwindcss@3.4.17 via ^8.4.47, vite@8.0.16 via ^8.5.15) already admitted a patched version, so this is a lockfile refresh (yarn up -R postcss) with no package.json change and no new resolutions override.

Note: the branch is named cursor/cve/postcss-8.5.25 rather than cursor/cve/postcss because the latter is still occupied by a stale branch from closed PR #1285.

Verification

  • yarn why postcss reports 8.5.25 for every requester; yarn.lock contains a single postcss entry and no 8.5.22 remains in the graph.
  • yarn workspace @sourcebot/web lint is clean.
  • yarn build (full monorepo, including the Next.js/Tailwind PostCSS pipeline) succeeds.
  • yarn test passes (1760 tests across queryLanguage, shared, backend, web).

🤖 Generated with Claude Code


Note

Low Risk
Lockfile-only transitive dependency bump for a known PostCSS CVE; no application code or dependency range changes, with build/lint/test verification reported in the PR.

Overview
Bumps the resolved postcss version in yarn.lock from 8.5.22 to 8.5.25 to address CVE-2026-69153 (information disclosure via crafted sourceMappingURL in source-map loading). No package.json or resolutions changes—existing semver ranges already allowed a patched release; this is a lockfile refresh.

Documents the upgrade under [Unreleased] → Fixed in CHANGELOG.md.

Reviewed by Cursor Bugbot for commit d2fc270. Bugbot is set up for automated code reviews on this repo. Configure here.

claude Bot and others added 2 commits August 5, 2026 02:22
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️ Status: PASS

Metric Count
Total packages 2196
Resolved (non-standard) 17
Unresolved 0
Strong copyleft 0
Weak copyleft 28

Weak Copyleft Packages (informational)

Package Version License
@img/sharp-libvips-darwin-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-wasm32 0.35.3 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm64 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
axe-core 4.10.3 MPL-2.0
dompurify 3.4.12 (MPL-2.0 OR Apache-2.0)
lightningcss 1.32.0 MPL-2.0
lightningcss-android-arm64 1.32.0 MPL-2.0
lightningcss-darwin-arm64 1.32.0 MPL-2.0
lightningcss-darwin-x64 1.32.0 MPL-2.0
lightningcss-freebsd-x64 1.32.0 MPL-2.0
lightningcss-linux-arm-gnueabihf 1.32.0 MPL-2.0
lightningcss-linux-arm64-gnu 1.32.0 MPL-2.0
lightningcss-linux-arm64-musl 1.32.0 MPL-2.0
lightningcss-linux-x64-gnu 1.32.0 MPL-2.0
lightningcss-linux-x64-musl 1.32.0 MPL-2.0
lightningcss-win32-arm64-msvc 1.32.0 MPL-2.0
lightningcss-win32-x64-msvc 1.32.0 MPL-2.0
Resolved Packages (17)
Package Version Original Resolved Source
@sentry/cli 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API (license=FSL-1.1-MIT) + GitHub repo LICENSE at tag 2.58.5 (Functional Source License, Version 1.1, MIT Future License). Real license, but not an SPDX-registered identifier.
@sentry/cli-darwin 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API (license=FSL-1.1-MIT) + GitHub repo LICENSE at tag 2.58.5 (Functional Source License, Version 1.1, MIT Future License). Real license, but not an SPDX-registered identifier.
@sentry/cli-linux-arm 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API (license=FSL-1.1-MIT) + GitHub repo LICENSE at tag 2.58.5 (Functional Source License, Version 1.1, MIT Future License). Real license, but not an SPDX-registered identifier.
@sentry/cli-linux-arm64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API (license=FSL-1.1-MIT) + GitHub repo LICENSE at tag 2.58.5 (Functional Source License, Version 1.1, MIT Future License). Real license, but not an SPDX-registered identifier.
@sentry/cli-linux-i686 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API (license=FSL-1.1-MIT) + GitHub repo LICENSE at tag 2.58.5 (Functional Source License, Version 1.1, MIT Future License). Real license, but not an SPDX-registered identifier.
@sentry/cli-linux-x64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API (license=FSL-1.1-MIT) + GitHub repo LICENSE at tag 2.58.5 (Functional Source License, Version 1.1, MIT Future License). Real license, but not an SPDX-registered identifier.
@sentry/cli-win32-arm64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API (license=FSL-1.1-MIT) + GitHub repo LICENSE at tag 2.58.5 (Functional Source License, Version 1.1, MIT Future License). Real license, but not an SPDX-registered identifier.
@sentry/cli-win32-i686 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API (license=FSL-1.1-MIT) + GitHub repo LICENSE at tag 2.58.5 (Functional Source License, Version 1.1, MIT Future License). Real license, but not an SPDX-registered identifier.
@sentry/cli-win32-x64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API (license=FSL-1.1-MIT) + GitHub repo LICENSE at tag 2.58.5 (Functional Source License, Version 1.1, MIT Future License). Real license, but not an SPDX-registered identifier.
codemirror-lang-elixir 4.0.0 UNKNOWN Apache-2.0 GitHub repo LICENSE (GitHub API SPDX detection: Apache-2.0) + bundled LICENSE file
khroma 2.1.0 UNKNOWN MIT GitHub repo LICENSE (GitHub API SPDX detection: MIT) + bundled LICENSE file
lezer-elixir 1.1.2 UNKNOWN Apache-2.0 GitHub repo LICENSE (GitHub API SPDX detection: Apache-2.0) + bundled LICENSE file
map-stream 0.1.0 UNKNOWN MIT GitHub repo LICENCE (GitHub API SPDX detection: MIT) + bundled LICENCE file
memorystream 0.3.1 UNKNOWN MIT extracted from object (npm registry licenses[0].type = MIT) + GitHub repo LICENSE
pause-stream 0.0.11 ["MIT", "Apache2"] MIT OR Apache-2.0 extracted from object (package.json license array ["MIT","Apache2"]) + repo LICENSE stating "Dual Licensed MIT and Apache 2" with both full texts
posthog-js 1.369.0 SEE LICENSE IN LICENSE Apache-2.0 bundled LICENSE file referenced by the license field (Apache-2.0; trailing MIT notices apply only to vendored third-party snippets)
valid-url 1.0.9 UNKNOWN MIT bundled LICENSE file (verbatim MIT text; GitHub reports NOASSERTION only because the title line is absent)

@brendan-kellam
brendan-kellam merged commit a83675c into main Aug 5, 2026
11 checks passed
@brendan-kellam
brendan-kellam deleted the cursor/cve/postcss-8.5.25 branch August 5, 2026 02:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant