Skip to content

Dependabot: postcss < 8.5.10 transitive (XSS in CSS stringify, CVE-2026-41305) #63

Description

@thiras

Alert

Dependabot alert #1 — security/dependabot/1, surfaced by the CodeQL check summary on #62.

Field Value
Package postcss (npm)
Vulnerable range < 8.5.10
First patched 8.5.10
Severity medium (CVSS 6.1)
Advisory GHSA-qx2v-qp2m-jg93 / CVE-2026-41305
CWE CWE-79 (XSS)

Where it comes from

pnpm why postcss shows two copies; only the runtime one is vulnerable:

postcss@8.4.31     ← vulnerable
└─ next@16.2.4 → website (dependencies)

postcss@8.5.13     ← already patched, ignore
└─ @tailwindcss/postcss@4.2.4 → website (devDependencies)

The vulnerable instance is a transitive dep of next, not in package.json.

Practical exploitability for this site

The advisory requires user-submitted CSS to be parsed and re-stringified. This site is a static-export marketing page (output: "export", see AGENTS.md); postcss only runs at build time over our own source files. Exploit prerequisites are not present, so impact is informational — the alert still needs to clear from the security tab.

Fix options

  1. Wait for a Next.js bump that pulls postcss >= 8.5.10 transitively. Cheapest. Check at the next minor release.
  2. pnpm override in package.json (recommended explicit fix — dedupes both copies and silences the alert):
    "pnpm": {
      "overrides": {
        "postcss": ">=8.5.10"
      }
    }
    Then pnpm install and re-run pnpm build to verify nothing breaks.
  3. pnpm update postcss — works only if pnpm's resolver picks the new version under next's constraint.

Acceptance

  • Dependabot alert feat: deCDN marketing one-pager #1 transitions to fixed
  • pnpm build succeeds
  • pnpm why postcss reports a single copy >= 8.5.10 (or both copies on patched versions)

Activity

  1. thiras commented on May 11, 2026

    @thiras
    ContributorAuthor

    we'll wait nextjs bump

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency file

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions