CVE-2026-69153

Aliases:RHSA-2026:50070UBUNTU-CVE-2026-69153DEBIAN-CVE-2026-69153GHSA-fxqj-rqcc-2cmpCGA-2j6r-74qg-353vCGA-2pv2-22v6-g75pCGA-342v-hj42-j8f4CGA-34rh-728g-6xwgCGA-37gq-32rj-4hrgCGA-3mfv-cpq2-fgg2CGA-3vx3-732h-gg9jCGA-49c2-26v8-ghv6CGA-55j9-grmq-pxpqCGA-59jr-hprh-jp8qCGA-5gw9-hxjj-h69vCGA-77jh-mgqp-r5jqCGA-89hf-hcg9-4w4fCGA-986v-cj7h-2c5cCGA-9w4p-g529-gxmpCGA-c7g7-pm5h-649fCGA-c829-rv62-xxfxCGA-gg56-jjwv-j22pCGA-h3qc-f67m-5f3cCGA-jr94-pg6j-f79fCGA-m6qp-p2jf-x98jCGA-mv3v-7grr-22x3CGA-pwq4-j8vq-838rCGA-24rq-qxmv-45xjCGA-252w-4qgx-3f93CGA-28gr-qxwf-8fw8CGA-2jq7-qxp3-3578CGA-2r2x-7pr5-fw98CGA-32jx-3xxg-5cjqCGA-35mm-6g28-x983CGA-39fc-c88x-jmrwCGA-3cmw-r3xx-4r8gCGA-3fm6-hghg-xwmjCGA-435c-9phh-ccqfCGA-4cp6-9v3q-w639CGA-4g3v-wg2v-f66vCGA-4gg7-jq52-gr66CGA-4h82-rgw9-5p26CGA-4jrm-4fv6-rxvpCGA-4vh3-6m62-57jxCGA-4wpw-vqcv-83mhCGA-4wrh-mmg2-4gw6CGA-5548-pw8p-p5c8CGA-5jwq-g46v-cc2cCGA-5m4q-h8qf-j4h9CGA-5q9j-hx4h-6m37CGA-5qg2-4jwx-ghxhCGA-68mj-v2hr-w869CGA-6gqx-63pm-9hf3CGA-6m6p-9crv-v53hCGA-6pw6-7526-23cvCGA-6v83-fc4w-29vwCGA-6whp-wpjh-q77cCGA-73rw-xg86-4c99CGA-7fxq-prmg-3vgcCGA-7gr6-ghx5-cp92CGA-7hrc-hv88-fr3gCGA-7q9g-w8r8-5fp7CGA-7qm2-9q7j-rwr5CGA-7v9h-pwxx-47hwCGA-7x76-83qq-x6pqCGA-7xpm-7wh4-75j9CGA-843f-59gv-3crrCGA-862q-9jq7-frxxCGA-867x-xrg8-9hmmCGA-8fh3-vqmp-jw34CGA-8qmf-fw2w-5rc2CGA-8w8h-f56h-72wfCGA-8xjf-vpc3-mh4xCGA-9cgv-c438-6xxpCGA-9fcm-7r8r-5q2hCGA-9hr6-xcxx-f3ccCGA-9pww-jj38-x792CGA-9q6r-qg64-cq5qCGA-9xp6-8pw4-gw3wCGA-c4hg-9792-62vfCGA-c8mr-74jg-ph3vCGA-c999-cm9v-rw64CGA-crj8-2r8m-gq56CGA-cx2m-cjw3-w45rCGA-cx4m-w7jx-wjmfCGA-cxv9-3r6r-33cfCGA-f4cm-5wx6-f9v6CGA-fpxr-wjcr-qcmvCGA-fxfq-qp6r-hf9mCGA-g22h-f2v3-qv9wCGA-g422-mmw3-xxwrCGA-g4j3-g8v6-f55wCGA-g5wr-695x-wv7vCGA-g67q-8p93-vf63CGA-g9qq-ghvp-v7hcCGA-ggv3-3pxq-3g2xCGA-gqqx-xq5j-gj3jCGA-h78c-rfcv-3j22CGA-h96g-m5qg-3p64CGA-hcmp-7xhc-g2m3CGA-hh73-cmf3-wxgqCGA-hhxp-gh4c-mmpvCGA-hm8f-3rc6-mc6qCGA-j2pm-rw92-ww37CGA-j393-8926-2xr9CGA-j3f7-g72r-28f9CGA-j7mf-749c-4gq5CGA-j7p3-f53j-gwjvCGA-jh5g-xp37-6p8cCGA-jmw2-x239-43xwCGA-jqv7-m7fp-jm86CGA-jvqg-pc8c-mv5qCGA-m3x6-m3mp-q5gxCGA-m7v5-x7c7-42pvCGA-mcrg-mr4c-6w55CGA-mfrx-4pg6-59q6CGA-p7wm-f567-8r5pCGA-p87p-5pvf-4pphCGA-pcpm-h67m-c74rCGA-pfgj-7wmc-c3cjCGA-pgcw-f8x3-jx5qCGA-pmxm-m84g-f7qrCGA-pqqg-p36h-jj2mCGA-q76w-f8gc-37wxCGA-qc53-x2v7-4388CGA-qhrr-j4w4-p63jCGA-qq69-2hqw-89c4CGA-qqg9-vc7p-3pghCGA-r789-4xqx-4whgCGA-r79v-843q-gm29CGA-r7wj-wph7-jrrjCGA-r9w9-pv6p-w4gjCGA-rgh9-x77m-cp8fCGA-rh45-cc72-qwc8CGA-rmh8-x33h-4x82CGA-rpqm-vxc2-3f6gCGA-rv43-gwrg-ccmwCGA-rvvm-p73j-v6v6CGA-rw6g-7x3f-q6m8CGA-rxhp-qj5v-9r7jCGA-v35r-9r4q-mj6qCGA-v48r-fq2v-r9xrCGA-v495-v5r8-pmfgCGA-v5j8-9r7v-3mmgCGA-v6cx-xc6w-rjwhCGA-vf6c-rc22-xgcmCGA-vmp8-8x8f-c5j5CGA-vr83-3pgw-vc55CGA-vrwg-vmrg-9qvvCGA-vv75-fqmr-x4m4CGA-vw7v-pqvh-rc98CGA-w3c4-rpxv-qjchCGA-w6jx-j3v3-wgfhCGA-w7g5-h63q-x76cCGA-wf98-95pc-5vvpCGA-wg9f-5vcf-v9xvCGA-wrjf-wjjw-ghm2CGA-wwg7-pfg8-3xxxCGA-wwxj-4f8m-759pCGA-x62g-qr3j-vp66CGA-x8p3-6wwr-97pjCGA-xqp9-3q4p-pxffCGA-xv63-77mj-6x6rCGA-xxhw-v5q3-x5mrCGA-4gj3-4wc3-ww3vCGA-6cg4-rg2q-gjjqCGA-gjfx-85wc-h6j2CGA-4hqh-wfx7-54jgCGA-8qm8-gxrp-4c7hCGA-gp56-wh43-cj5hCGA-r4rw-28gv-jfrrCGA-wfg2-mqjp-pp9qCGA-x53h-jjmp-fxrqCGA-4w4q-q6wr-wcx3CGA-6x95-x3rh-xf28CGA-7px8-fgc6-5wqvCGA-pqmc-532j-rhx2
Analyzed
Published: 03 Aug 2026, 16:56
Last modified:03 Aug 2026, 18:28

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
6.3 MEDIUM
v4.0 (cve.org)
EPSS Score
0.45% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

03 Aug 2026, 16:56
Published
Vulnerability first disclosed
03 Aug 2026, 18:28
Last Modified
Vulnerability information updated

Description

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.

CVSS Metrics

  • v4.0MEDIUMScore: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
  • v4.0MEDIUMScore: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS Trends

Current EPSS score: 0.45% Percentile: 39%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardarangodb-3.11

    < 3.11.14.5-r1

  • chainguardarangodb-3.12

    < 3.12.9.4-r22

  • chainguardauthentik-2025.12

    < 2025.12.6-r6

  • chainguardauthentik-2026.2

    < 2026.2.6-r11

  • chainguardauthentik-2026.5

    < 2026.5.6-r3

  • chainguardauthentik-fips-2025.12

    all

  • chainguardauthentik-fips-2026.5

    < 2026.5.6-r3

  • chainguardcadence-web

    < 4.0.16-r6

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r6

  • chainguardgitlab-rails-ce-fips-18.1

    all

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    all | < 19.1.7-r7

  • chainguardgitlab-rails-ce-fips-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-fips-19.3

    < 19.3.1-r3

  • chainguardjupyter-base-notebook

    all

  • chainguardkeep-ui

    < 0.54.2-r2

  • chainguardkeep-ui-fips

    < 0.54.2-r4

  • chainguardkubeflow-pipelines-apiserver

    < 2.17.2-r4

  • chainguardkubeflow-pipelines-frontend

    < 2.17.0-r3

  • chainguardkubeflow-pipelines-metadata-writer-compat

    < 2.17.2-r4

  • chainguardlangfuse-3-compat

    < 3.225.7-r6

  • chainguardlangfuse-3-worker

    < 3.225.1-r2

  • chainguardlangfuse-4-worker

    < 4.6.0-r0

  • chainguardlangfuse-fips-3-worker

    < 3.225.1-r2

  • chainguardlangfuse-fips-4-worker

    < 4.4.0-r0

  • chainguardnextcloud-server-31

    < 31.0.14-r6

Showing first 50 affected entries in server-rendered view.

References (15)