# postcss@8.5.23 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:22:43.000Z
- Files reviewed: 29
- Findings: 1 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/postcss@8.5.23
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package postcss@8.5.23 on Oct 6, 2026. An AI review of 29 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Path Traversal Risk in Source Map Loading

Finding ID: `NPS-30F160823F9F`

File: `lib/previous-map.js:85`

The loadFile method attempts to restrict loading of source maps to files within the CSS file's directory by checking relative paths. However, the guard is only applied when 'trusted' is false and 'unsafeMap' is not set. In the loadMap method, when 'prev' is a function, loadFile is called with trusted=true, bypassing these checks entirely. If an attacker can control the 'prev' function or its return value (e.g., via a crafted build configuration or plugin), they could load arbitrary files from the filesystem. Additionally, the check uses string operations that may be bypassed with edge cases like symlinks or non-normalized paths.

### [low] Prototype manipulation via __proto__ assignment

Finding ID: `NPS-17A1E22AD8ED`

File: `lib/fromJSON.js:13`

The hydrateInputs function constructs objects with literal '__proto__' properties: '{ ...input, __proto__: Input.prototype }' and '{ ...inputHydrated.map, __proto__: PreviousMap.prototype }'. While this appears intended to rehydrate class instances from JSON, setting '__proto__' explicitly is widely flagged as a dangerous pattern because it can be abused for prototype pollution. In this specific file the value is a hard-coded library prototype (not attacker-controlled), so it does not directly enable pollution, but it is a fragile and security-sensitive construct worth noting.

### [low] Unsafe spread of untrusted JSON into object prototypes

Finding ID: `NPS-D1A1817D0529`

File: `lib/fromJSON.js:23`

constructNode does 'let defaults = { ...json }' on data coming from JSON (potentially untrusted input to fromJSON). If any nested property named '__proto__' or 'constructor' is present in the JSON, spread/merge semantics could interact with prototype chains depending on runtime and downstream constructors. This mirrors known prototype-pollution risks in deserialization helpers.

### [low] Unsafe Base64 Decoding Fallback to window.atob

Finding ID: `NPS-F20379FF7B44`

File: `lib/previous-map.js:6`

The fromBase64 function uses Buffer.from(str, 'base64').toString() when Buffer is available, but falls back to window.atob(str) otherwise. In Node.js, Buffer is always available, so the fallback is unreachable in server-side contexts. However, if the code is bundled for browser use, window.atob is used. This is not inherently malicious, but the dynamic nature of the fallback and the fact that it decodes inline source maps could be abused if an attacker controls the source map data to cause memory exhaustion or unexpected behavior. The risk is low given typical usage.

## Files reviewed

- `lib/fromJSON.js` (medium): No exfiltration, credential harvesting, shell execution, network calls, or install-time hooks were found; the only concerns are the explicit __proto__ assignments during instance rehydration, which are a security-sensitive but hard-coded pattern.
- `lib/previous-map.js` (medium): The code is a legitimate source map handling utility with no obvious malicious patterns, but it contains a potential path traversal bypass in its source map loading logic when a trusted previous map function is provided.
- `lib/at-rule.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/comment.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/container.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/css-syntax-error.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/declaration.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/document.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/input.js` (safe): No malicious patterns detected; the file is legitimate PostCSS input handling code with no exfiltration, credential harvesting, dynamic execution, or suspicious network/file/process activity.
- `lib/lazy-result.js` (safe): No malicious patterns detected; this is a legitimate PostCSS LazyResult implementation with no data exfiltration, credential harvesting, dynamic code execution, or suspicious network/file/process activity.
- `lib/list.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/map-generator.js` (safe): The file is a standard PostCSS source map generator with no malicious patterns, network activity, process spawning, obfuscation, or credential access.
- `lib/no-work-result.js` (safe): No malicious patterns detected; the file is a standard PostCSS result wrapper with no network, filesystem, process, or dynamic code execution activity.
- `lib/node.js` (safe): This is the standard PostCSS Node class implementation with no malicious patterns; it handles CSS AST manipulation, cloning, and serialization without network, filesystem, or process operations.
- `lib/parse.js` (safe): No malicious patterns detected
- `lib/parser.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/postcss.js` (safe): No malicious patterns detected; the file is a standard PostCSS module entry point with only legitimate requires, exports, and a deprecated plugin helper.
- `lib/postcss.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `lib/processor.js` (safe): No malicious patterns detected; the code is a standard PostCSS Processor implementation with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `lib/result.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/root.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rule.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/stringifier.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/stringify.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/symbols.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/terminal-highlight.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/tokenize.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/warn-once.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/warning.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 2 scanned versions of postcss are flagged high or critical. The latest scanned version, 8.5.28, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 8.5.28 (`8.5.28`): medium
- 8.5.25 (`8.5.25`): not scanned
- 8.5.23 (`8.5.23`): medium (Path Traversal Risk in Source Map Loading)
- 7.0.39 – 8.4.49 (`>=7.0.39 <=8.4.49`): not scanned

## Scanned versions

- [8.5.28](https://security.togoder.click/npm/postcss@8.5.28): medium, 2026-10-06T14:23:45.000Z
- [8.5.23](https://security.togoder.click/npm/postcss@8.5.23): medium, 2026-10-06T14:22:43.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
