CVE-2026-49356

EUVD-2026-38302
Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the system that is running Babel, if the attacker controls the input source code, can read the output source code, and knows the path of the source map file that they want to read. This vulnerability is fixed in 8.0.0-rc.6 and 7.29.6.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.2 LOW
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 2.65%
Affected Products (NVD)
VendorProductVersion
babelbabel
𝑥
< 7.29.6
babelbabel
8.0.0:alpha0
babelbabel
8.0.0:alpha1
babelbabel
8.0.0:alpha10
babelbabel
8.0.0:alpha11
babelbabel
8.0.0:alpha12
babelbabel
8.0.0:alpha13
babelbabel
8.0.0:alpha14
babelbabel
8.0.0:alpha15
babelbabel
8.0.0:alpha16
babelbabel
8.0.0:alpha17
babelbabel
8.0.0:alpha2
babelbabel
8.0.0:alpha3
babelbabel
8.0.0:alpha4
babelbabel
8.0.0:alpha5
babelbabel
8.0.0:alpha6
babelbabel
8.0.0:alpha7
babelbabel
8.0.0:alpha8
babelbabel
8.0.0:alpha9
babelbabel
8.0.0:beta0
babelbabel
8.0.0:beta1
babelbabel
8.0.0:beta2
babelbabel
8.0.0:beta3
babelbabel
8.0.0:beta4
babelbabel
8.0.0:rc1
babelbabel
8.0.0:rc2
babelbabel
8.0.0:rc3
babelbabel
8.0.0:rc4
babelbabel
8.0.0:rc5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-babel7
bookworm
postponed
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
vulnerable
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
babel
jammy
dne
noble
dne
questing
dne
resolute
dne