Uncontrolled Recursion Vulnerability in PostCSS Product by Vendor
CVE-2026-9358
Key Information:
Badges
What is CVE-2026-9358?
A vulnerability exists in PostCSS versions up to 7.1.1 within the function toString located in the component AST Serialization at src/selectors/container.js. This flaw can lead to uncontrolled recursion, potentially allowing an attacker to exploit it remotely. Although the vendor has indicated that the risk may be low for server-side scenarios involving user-generated CSS (as most users compile their own CSS), the public disclosure of this exploit raises concerns about its potential misuse.
Affected Version(s)
postcss 7.1.0
postcss 7.1.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
