StackRadar

CVE-2026-69153

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.005
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
255
of 17,787 indexed, latest versions
Container images
256
deployed by those charts
Fix available
1 of 2
affected packages

PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset

Carried by container images the latest versions of 255 of 17,787 indexed charts deploy, on 256 images.

Affected packageAffected versionsFixed inImages
postcssnpm4.1.16, 5.2.18, 6.0.17, 6.0.22+54 more8.5.23256
node-postcssdeb8.4.31+~cs8.0.26-1, 8.4.49+~cs9.2.32-1no fix listed2
OSV records
DEBIAN-CVE-2026-69153GHSA-fxqj-rqcc-2cmpUBUNTU-CVE-2026-69153

Charts affected

255 by stars
ChartLatestAffected imagesRadar Score
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-69153.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
postcss@8.4.49
8.5.23

Open the chart page →

6,470
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-69153.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
postcss@8.4.31
8.5.23

Open the chart page →

5,774
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2026-69153.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
postcss@6.0.23
8.5.23

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2026-69153.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
postcss@6.0.23
8.5.23

Open the chart page →

22,665
workadventureworkadventure1.1.03 of 9See more

workadventure workadventure 1.1.0

3 of the 9 container images this version deploys carry CVE-2026-69153.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
postcss@8.4.31
8.5.23
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
postcss@8.4.31
8.5.23
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
postcss@8.4.31
8.5.23

Open the chart page →

16,083

Container images carrying it

256 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
postcss@7.0.36
8.5.23
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
postcss@8.4.31
8.5.23
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
postcss@8.4.13
8.5.23
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
postcss@8.4.31
8.5.23
3
chatwoot/chatwoot:v3.1.0d530ab8c1753
postcss@7.0.35
8.5.23
2
governify/assets-manager:v1.4.12987672448c7
postcss@7.0.35
8.5.23
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
postcss@8.4.40
8.5.23
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
postcss@7.0.36
8.5.23
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
postcss@7.0.35
8.5.23
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
postcss@7.0.39
8.5.23
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
postcss@7.0.39
8.5.23
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
postcss@7.0.39
8.5.23
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
postcss@8.5.6
8.5.23
2
outlinewiki/outline:0.69.1d060dcd8f9aa
postcss@8.4.21
8.5.23
2
rajnandan1/kener:3.2.1930407afca731
postcss@8.5.1
8.5.23
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postcss@8.3.0
8.5.23
2
sysnet4admin/dashboard:bluec5bd3bb1b5a6
postcss@8.4.31
8.5.23
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
postcss@7.0.39
8.5.23
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
postcss@8.4.31
8.5.23
2
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
postcss@8.5.6
8.5.23
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
postcss@8.5.8
8.5.23
1
alquimiaai/studio:certification38a1f0341982
postcss@8.4.31
8.5.23
1
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
postcss@7.0.17
8.5.23
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
postcss@7.0.23
8.5.23
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
postcss@8.4.45
8.5.23
1
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
postcss@8.4.31
8.5.23
1
apimap/developer:v1.3.1406d3858e20c
postcss@7.0.39
8.5.23
1
apimap/portal:v2.4.0041a4790c65c
postcss@8.4.14
8.5.23
1
arfath29/3-tier-app-frontend:latest384b3e377f47
postcss@7.0.36
8.5.23
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
postcss@7.0.32
8.5.23
1
assistiot/open_api_frontend:1.0.1f11d82defc70
postcss@8.4.21
8.5.23
1
automatischio/automatisch:0.15.03bace7a12d5f
postcss@8.5.3
8.5.23
1
baserow/baserow:1.30.1df0c42eb67e8
postcss@8.4.32
8.5.23
1
ccjacobs14/amazon:59a9b14a6f09e
postcss@8.4.23
8.5.23
1
chainsafe/lodestar:latest5593f6e97912
postcss@8.5.6
8.5.23
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
postcss@8.4.39
8.5.23
1
chatwoot/chatwoot:v4.15.167ebc751c171
postcss@7.0.35
8.5.23
1
chibisafe/chibisafe:latest836467a50792
postcss@8.4.31
8.5.23
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
postcss@8.4.37
8.5.23
1
chocobozzz/peertube:v8.1.5052712130691
postcss@8.5.6
8.5.23
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
postcss@6.0.23
8.5.23
1
codetogether/codetogether:latest4348c8a38752
postcss@7.0.39
8.5.23
1
coldatom/containers-security-front:latest7c2fbbb41bcf
postcss@7.0.39
8.5.23
1
conduction/conduction-ui-app:devd591f5e6f2a9
postcss@7.0.35
8.5.23
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
postcss@8.5.15
8.5.23
1
daskdev/dask-notebook:1.1.0052630f5ca04
postcss@5.2.18
8.5.23
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
postcss@8.4.41
8.5.23
1
devopsiaci/self-learning-platform:1.1.3d9441c931f75
postcss@8.4.31
8.5.23
1
directus/directus:12.0.29c8470ea465c
postcss@8.5.15
8.5.23
1
directus/directus:11.1.0e3c8bb975350
postcss@8.4.41
8.5.23
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.