PostCSS line return parsing error
GHSA-7fh5-64p2-3v2j · CVE-2023-44270
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
An issue was discovered in PostCSS before 8.4.31. It affects linters using PostCSS to parse external Cascading Style Sheets (CSS). There may be \r discrepancies, as demonstrated by @font-face{ font:(\r/*);} in a rule.
This vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being originally included in a comment.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2023-44270
- WEB https://github.com/github/advisory-database/issues/2820
- WEB https://github.com/postcss/postcss/commit/58cc860b4c1707510c9cd1bc1fa30b423a9ad6c5
- PACKAGE https://github.com/postcss/postcss
- WEB https://github.com/postcss/postcss/blob/main/lib/tokenize.js#L25
- WEB https://github.com/postcss/postcss/releases/tag/8.4.31
- WEB https://lists.debian.org/debian-lts-announce/2024/12/msg00025.html
Ready to move
Start Securing
Free, no credit card | First findings in minutes