CVE-2023-44270

unknown
Published 2023-09-30 · Modified 2025-11-04
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v2
VIR risk

Description

An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being included in a comment.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-44270

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed8.4.20+~cs8.0.23-1+deb12u1
debian debianbullseyefixed8.2.1+~cs5.3.23-8+deb11u1
debian debianforkyfixed8.4.31+~cs8.0.26-1
debian debiansidfixed8.4.31+~cs8.0.26-1
debian debiantrixiefixed8.4.31+~cs8.0.26-1

Package impact

EcosystemPackageVulnerableFixed
npm npmpostcss<8.4.318.4.31

References

Verify integrity in audit chain (admin only). AS-IS.