CVE-2023-44270

An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being included in a comment.

Fixed
LOW (2.8)
  • T

    Tim Bastin detected CVE-2023-44270 with a risk of 0.93

  • logo

    System updated the risk assessment to 0.7

    System recalculated raw risk assessment

  • T

    Tim Bastin fixed CVE-2023-44270

  • T

    Tim Bastin detected CVE-2023-44270 with a risk of 0.93

  • logo

    System updated the risk assessment to 0.7

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment to 2.8

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment to 0.7

    System recalculated raw risk assessment

  • T

    Tim Bastin fixed CVE-2023-44270

  • logo

    System updated the risk assessment to 2.8

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment from 2.8 to 2.45

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment from 2.45 to 2.8

    System recalculated raw risk assessment

Reopen this vulnerability

You can reopen this vuln, if you plan to mitigate the risk now, or accepted this vuln by accident.

Last calculated at:

Affected component

Logo von npm postcss

Installed version:
7.0.39
Fixed in:
8.4.31

Quick Fix

Update all Dependencies
Update only postcss
Copyright © 2025 L3montree GmbH and the DevGuard Contributors. All rights reserved. Version 667098114b5ef45c7830e7aa599604fa65eb818f