Skip to content

PEAR-2670+2671: Fix XSS (postcss)#1733

Open
paribartandhakal wants to merge 3 commits into
developfrom
feat/fix-xss-postcss
Open

PEAR-2670+2671: Fix XSS (postcss)#1733
paribartandhakal wants to merge 3 commits into
developfrom
feat/fix-xss-postcss

Conversation

@paribartandhakal

@paribartandhakal paribartandhakal commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Description

All project-controlled PostCSS versions satisfy >= 8.5.10.
The remaining vulnerable PostCSS version comes from next@16.2.9, which hard-pins postcss@8.4.31.
No stable next 16.x version currently fixes this.

https://security.snyk.io/vuln/SNYK-JS-POSTCSS-16189065

Checklist

  • Added proper unit tests
  • Left proper TODO messages for any remaining tasks
  • Scanned for web accessibility with aXe, and mitigated or documented
    flagged issues

Screenshots/Screen Recordings (if

Screenshot 2026-06-10 at 2 43 28 PM Appropriate)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant