7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether postcss is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-45623
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
MEDIUM 6.1
CVE-2026-41305
PostCSS has XSS via Unescaped </style> in its CSS Stringify Output
UNKNOWN
CVE-2026-69153
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
HIGH 7.5
CVE-2026-73646
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
MEDIUM 5.3
CVE-2023-44270
PostCSS line return parsing error
MEDIUM 5.3
CVE-2021-23368
Regular Expression Denial of Service in postcss
MEDIUM 5.3
CVE-2021-23382
Regular Expression Denial of Service in postcss
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes