Uncontrolled Recursion Vulnerability in PostCSS Product by Vendor
CVE-2026-9358

5.3MEDIUM

Key Information:

Vendor

PostCSS

Vendor
CVE Published:
24 May 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-9358?

A vulnerability exists in PostCSS versions up to 7.1.1 within the function toString located in the component AST Serialization at src/selectors/container.js. This flaw can lead to uncontrolled recursion, potentially allowing an attacker to exploit it remotely. Although the vendor has indicated that the risk may be low for server-side scenarios involving user-generated CSS (as most users compile their own CSS), the public disclosure of this exploit raises concerns about its potential misuse.

Affected Version(s)

postcss-selector-parser 6.1.0

postcss-selector-parser 6.1.1

postcss-selector-parser 6.1.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

bx33661 (VulDB User)
VulDB CNA Team
.