← Back

CVE-2026-49356

nvd nist
Published: Jun 22, 2026Modified: Jun 26, 2026

JSON object

Loading...
3.6
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Exploitability: 1.8 / Impact: 1.4
Source: NVD

Description

Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the system that is running Babel, if the attacker controls the input source code, can read the output source code, and knows the path of the source map file that they want to read. This vulnerability is fixed in 8.0.0-rc.6 and 7.29.6.

Affected (29)

Products: Babel: Babel
1 product
Babel
Configuration A
29 vulnerable
Vulnerable SoftwareAffected Versions
Babel
Before 7.29.6
Version 8.0.0 alpha0
Version 8.0.0 alpha10
Version 8.0.0 alpha11
Version 8.0.0 alpha12
Version 8.0.0 alpha13
Version 8.0.0 alpha14
Version 8.0.0 alpha15
Version 8.0.0 alpha16
Version 8.0.0 alpha17
Version 8.0.0 alpha1
Version 8.0.0 alpha2
Version 8.0.0 alpha3
Version 8.0.0 alpha4
Version 8.0.0 alpha5
Version 8.0.0 alpha6
Version 8.0.0 alpha7
Version 8.0.0 alpha8
Version 8.0.0 alpha9
Version 8.0.0 beta0
Version 8.0.0 beta1
Version 8.0.0 beta2
Version 8.0.0 beta3
Version 8.0.0 beta4
Version 8.0.0 rc1
Version 8.0.0 rc2
Version 8.0.0 rc3
Version 8.0.0 rc4
Version 8.0.0 rc5

References (1)

Source: security-advisories@github.com
MitigationVendor Advisory

Timeline

No history available yet.