Executive brief
PostCSS is a popular CSS parsing and processing library used in web development pipelines. When user-supplied CSS is parsed and re-stringified for embedding in HTML style tags, the library fails to escape closing style tag sequences, allowing an attacker to break out of the style context and inject arbitrary JavaScript. This vulnerability requires user interaction (the CSS must be processed and embedded in a web page) and affects applications that dynamically generate styles from untrusted input.
Technical details
This is a cross-site scripting (XSS) vulnerability in PostCSS's CSS stringification process. The root cause is that when PostCSS converts its Abstract Syntax Tree (AST) back to CSS string form, it does not escape </style> sequences found in CSS values. An attacker can inject CSS like `content: "</style><script>alert(1)</script><style>"` which, when re-stringified and embedded in an HTML style tag, breaks out of the style context and executes arbitrary JavaScript in the browser. The attack vector is network-based and requires no authentication, but does require user interaction (the malicious CSS must be processed and the resulting HTML served to a victim). The vulnerability affects PostCSS versions before 8.5.10; a patch is available that escapes </style sequences during stringification.
Affected products
- PostCSS PostCSS <8.5.10
Timeline
- 2026-04-20: disclosed
- 2026-04-24: patched: version 8.5.10 released with fix