StackRadar

CVE-2026-73646

High

Advisory

Published 24 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
251
of 17,781 indexed, latest versions
Container images
251
deployed by those charts
Fix available
1 of 2
affected packages

PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure

Carried by container images the latest versions of 251 of 17,781 indexed charts deploy, on 251 images.

Affected packageAffected versionsFixed inImages
postcssnpm4.1.16, 5.2.18, 6.0.17, 6.0.22+51 more8.5.18251
node-postcssdeb8.4.31+~cs8.0.26-1no fix listed1
OSV records
GHSA-r28c-9q8g-f849UBUNTU-CVE-2026-73646

Charts affected

251 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.03 of 9See more

workadventure workadventure 1.1.0

3 of the 9 container images this version deploys carry CVE-2026-73646.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
postcss@8.4.31
8.5.18
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
postcss@8.4.31
8.5.18
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
postcss@8.4.31
8.5.18

Open the chart page →

16,083

Container images carrying it

251 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
postcss@7.0.36
8.5.18
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
postcss@8.4.31
8.5.18
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
postcss@8.4.13
8.5.18
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
postcss@8.4.31
8.5.18
3
chatwoot/chatwoot:v3.1.0d530ab8c1753
postcss@7.0.35
8.5.18
2
governify/assets-manager:v1.4.12987672448c7
postcss@7.0.35
8.5.18
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
postcss@8.4.40
8.5.18
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
postcss@7.0.36
8.5.18
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
postcss@7.0.35
8.5.18
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
postcss@7.0.39
8.5.18
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
postcss@7.0.39
8.5.18
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
postcss@7.0.39
8.5.18
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
postcss@8.5.6
8.5.18
2
outlinewiki/outline:0.69.1d060dcd8f9aa
postcss@8.4.21
8.5.18
2
rajnandan1/kener:3.2.1930407afca731
postcss@8.5.1
8.5.18
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postcss@8.3.0
8.5.18
2
sysnet4admin/dashboard:bluec5bd3bb1b5a6
postcss@8.4.31
8.5.18
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
postcss@7.0.39
8.5.18
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
postcss@8.4.31
8.5.18
2
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
postcss@8.5.6
8.5.18
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
postcss@8.5.8
8.5.18
1
alquimiaai/studio:certification38a1f0341982
postcss@8.4.31
8.5.18
1
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
postcss@7.0.17
8.5.18
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
postcss@7.0.23
8.5.18
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
postcss@8.4.45
8.5.18
1
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
postcss@8.4.31
8.5.18
1
apimap/developer:v1.3.1406d3858e20c
postcss@7.0.39
8.5.18
1
apimap/portal:v2.4.0041a4790c65c
postcss@8.4.14
8.5.18
1
arfath29/3-tier-app-frontend:latest384b3e377f47
postcss@7.0.36
8.5.18
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
postcss@7.0.32
8.5.18
1
assistiot/open_api_frontend:1.0.1f11d82defc70
postcss@8.4.21
8.5.18
1
automatischio/automatisch:0.15.03bace7a12d5f
postcss@8.5.3
8.5.18
1
baserow/baserow:1.30.1df0c42eb67e8
postcss@8.4.32
8.5.18
1
ccjacobs14/amazon:59a9b14a6f09e
postcss@8.4.23
8.5.18
1
chainsafe/lodestar:latest5593f6e97912
postcss@8.5.6
8.5.18
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
postcss@8.4.39
8.5.18
1
chatwoot/chatwoot:v4.15.167ebc751c171
postcss@7.0.35
8.5.18
1
chibisafe/chibisafe:latest836467a50792
postcss@8.4.31
8.5.18
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
postcss@8.4.37
8.5.18
1
chocobozzz/peertube:v8.1.5052712130691
postcss@8.5.6
8.5.18
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
postcss@6.0.23
8.5.18
1
codetogether/codetogether:latest4348c8a38752
postcss@7.0.39
8.5.18
1
coldatom/containers-security-front:latest7c2fbbb41bcf
postcss@7.0.39
8.5.18
1
conduction/conduction-ui-app:devd591f5e6f2a9
postcss@7.0.35
8.5.18
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
postcss@8.5.15
8.5.18
1
daskdev/dask-notebook:1.1.0052630f5ca04
postcss@5.2.18
8.5.18
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
postcss@8.4.41
8.5.18
1
devopsiaci/self-learning-platform:1.1.3d9441c931f75
postcss@8.4.31
8.5.18
1
directus/directus:12.0.29c8470ea465c
postcss@8.5.15
8.5.18
1
directus/directus:11.1.0e3c8bb975350
postcss@8.4.41
8.5.18
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.