Security vulnerabilities and automated fixes for build tools issues
1 post found
PostCSS versions prior to 8.5.12 contain an information disclosure vulnerability that allows attackers to read arbitrary files from the host system by crafting malicious CSS with a specially-formed sourceMappingURL comment. This vulnerability affects any application that processes untrusted CSS input, including CSS-in-JS frameworks, build tools, and web servers that normalize or transpile user-provided stylesheets.