Path traversal in Postcss - CVE-2026-45623
Published: July 22, 2026
Vulnerability identifier: #VU139097
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-45623
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in lib/previous-map.js. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
Postcss
Crowd Data Center
Confluence Data Center
Bamboo Data Center
Crowd Data Center
Confluence Data Center
Bamboo Data Center
How to mitigate CVE-2026-45623
Install updates from vendor's website.
Postcss - update to 8.5.12
Crowd Data Center - update to 7.2.2
Confluence Data Center - addressed in versions 9.2.22, 10.2.15
Bamboo Data Center - addressed in versions 10.2.21, 12.1.9
Crowd Data Center - update to 7.2.2
Confluence Data Center - addressed in versions 9.2.22, 10.2.15
Bamboo Data Center - addressed in versions 10.2.21, 12.1.9