cssparser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#readremotefile in lib/cssparser/parser.rb, and therefore loaduri! and the @import-following branch of addblock!, issued HTTP and HTTPS requests against any host, port, and URI without a scheme allowlist, host or IP filtering, or protection against link-local, loopback, or RFC-1918 addresses. Location: redirects were followed recursively back into the same function, which also serviced file:// URIs, so a single attacker-controlled HTTP redirect could upgrade the bug from SSRF to arbitrary local file disclosure. Any consumer of cssparser that hands it attacker-influenced CSS together with a baseuri: option is exposed. This issue is fixed in version 3.0.0.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53727.json",
"cwe_ids": [
"CWE-918"
],
"cna_assigner": "GitHub_M"
}