CVE-2026-73646 | PostCSS up to 8.5.17 Source Map lib/previous-map.js loadMap/loadFile opts.from/annotation information disclosure
A vulnerability marked as problematic has been reported in PostCSS up to 8.5.17. This vulnerability affects the function loadMap/loadFile of the file lib/previous-map.js of the component Source Map Handler. This manipulation of the argument opts.from/annotation causes information disclosure.
The identification of this vulnerability is CVE-2026-73646. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More