postcss-selector-parser is now locked at 7.1.6 in package-lock.json, so the vulnerable 6.1.4 is gone.
It only reaches the repo through postcss-nested (pulled in by tailwind), and postcss-nested ^6 asks for ^6.1.1, so a plain upgrade could not move it. I added an overrides entry "postcss-selector-parser": "^7.1.6" to package.json next to the existing fflate override, then refreshed the lockfile. The only changes are that override and the lockfile entry (version, resolved URL, integrity hash).
After the change, npm ci --ignore-scripts and npm test --if-present finished without errors, and npm run typecheck exited 0. I did not run the lockfile version-check command from the issue, but the lockfile now shows 7.1.6 for that entry. I did not confirm that the Tailwind/PostCSS build still works at runtime. postcss-nested 6.x was written against the 6.x parser, but nothing in the typecheck or tests exercises that. I also did not run cargo test, as the change doesn't touch Rust code.
An alternative is to upgrade postcss-nested to 7.0.2, which depends on the 7.x parser directly. I didn't take it because tailwind pins ^6.0.1, so it would have needed its own override anyway.