SecBoard
Zurück zur CVE-Übersicht

CVE-2026-44728

HIGH(8.2)

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Risk Signal Score21/100 — NIEDRIG
  • CVSS 8.2 — Hoch

Erwähnungen (letzte 60 Tage)

Artikel

EPSS-Score

0.1%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

8.2

Technische Schwere

Beschreibung

Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13.

GitHub Advisories

GHSA-fv7c-fp4j-7gwpHIGH

@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input

npm/@babel/plugin-transform-modules-systemjs7.29.4
GitHub Advisory

Referenzen