A high-severity vulnerability, CVE-2026-45623, has been identified in the npm package postcss affecting versions <= 8.5.11. This flaw allows an attacker who controls the CSS input to cause the host process to read any file readable by Node and leak the first ~10 bytes of its content through the resulting JSON.parse SyntaxError message. The bug also yields a precise file-existence oracle and a controllable-read primitive that may be combined with large-file targets for DoS. This vulnerability is triggered with PostCSS's default options — no from, no map, no plugins required — and is therefore reachable from any pipeline that runs untrusted CSS through PostCSS (CMS themes, user-uploaded styles, browser-extension/userstyle processors, build pipelines for third-party packages, blog comment renderers, etc.). An attacker can exploit this vulnerability via the environment template management API to read arbitrary files on the host system, including sensitive data such as app config, environment files, SSH keys. This could lead to a business impact of data loss or exposure, depending on the sensitivity of the data stored on the affected systems. The CVSS score for this vulnerability is 7.5.
We recommend you to update npm to version 8.5.12.[/subscribe_to_unlock_form]
A high-severity vulnerability, CVE-2026-45623, has been identified in the npm package postcss affecting versions <= 8.5.11. This flaw allows an attacker who controls the CSS input to cause the host process to read any file readable by Node and leak the first ~10 bytes of its content through the resulting JSON.parse SyntaxError message. The bug also yields a precise file-existence oracle and a controllable-read primitive that may be combined with large-file targets for DoS. This vulnerability is triggered with PostCSS's default options — no from, no map, no plugins required — and is therefore reachable from any pipeline that runs untrusted CSS through PostCSS (CMS themes, user-uploaded styles, browser-extension/userstyle processors, build pipelines for third-party packages, blog comment renderers, etc.). An attacker can exploit this vulnerability via the environment template management API to read arbitrary files on the host system, including sensitive data such as app config, environment files, SSH keys. This could lead to a business impact of data loss or exposure, depending on the sensitivity of the data stored on the affected systems. The CVSS score for this vulnerability is 7.5.
We recommend you to update npm to version 8.5.12.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]