Browse all 4 CVE security advisories affecting babel. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-49356 | Babel: Arbitrary File Read via sourceMappingURL Comment in @babel/core — babel CWE-22 | 3.2 | Low | 2026-06-22 |
| CVE-2026-44728 | Improper Control of Generation of Code when compiling specifically crafted malicious code with @babel/plugin-transform-modules-systemjs — babel CWE-94 | 8.2 | High | 2026-05-26 |
| CVE-2025-27789 | Inefficient RexExp complexity in generated code with .replace when transpiling named capturing groups — babel CWE-1333 | 6.2 | Medium | 2025-03-11 |
| CVE-2023-45133 | Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code — babel CWE-184 | 9.4 | Critical | 2023-10-12 |
This page lists every published CVE security advisory associated with babel. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.