{"id":"CVE-2023-44270","aliases":["GHSA-7fh5-64p2-3v2j"],"url":"https://o3.security/vulnerability/CVE-2023-44270","summary":"PostCSS line return parsing error","details":"An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being included in a comment.","published":"2023-09-29T00:00:00Z","modified":"2026-08-08T03:30:52.585256689Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"postcss","fixedVersion":"8.4.31"}],"fix":{"url":"https://github.com/postcss/postcss/commit/58cc860b4c1707510c9cd1bc1fa30b423a9ad6c5","label":"postcss/postcss@58cc860"},"references":[{"type":"WEB","url":"https://github.com/postcss/postcss/blob/main/lib/tokenize.js#L25"},{"type":"WEB","url":"https://github.com/postcss/postcss/releases/tag/8.4.31"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/12/msg00025.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/44xxx/CVE-2023-44270.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-44270"},{"type":"REPORT","url":"https://github.com/github/advisory-database/issues/2820"},{"type":"FIX","url":"https://github.com/postcss/postcss/commit/58cc860b4c1707510c9cd1bc1fa30b423a9ad6c5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:30:52.585256689Z"}}