CVE-2026-44728
Description
Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
CVE-2026-44728 NameCVE-2026-44728 DescriptionBabel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13. SourceCVE (at NVD; CERT, ENISA, LWN,โฆ
CVE-2026-44728
| Name | CVE-2026-44728 |
| Description | Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| node-babel7 (PTS) | bullseye (security), bullseye | 7.12.12+~cs150.141.84-6+deb11u1 | vulnerable |
| bookworm | 7.20.15+ds1+~cs214.269.168-3+deb12u2 | vulnerable | |
| bookworm (security) | 7.20.15+ds1+~cs214.269.168-3+deb12u1 | vulnerable | |
| trixie | 7.20.15+ds1+~cs214.269.168-8 | vulnerable | |
| forky, sid | 7.20.15+ds1+~cs214.269.168-17 | vulnerable |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| node-babel7 | source | (unstable) | (unfixed) |
Notes
https://github.com/babel/babel/security/advisories/GHSA-fv7c-fp4j-7gwp
Apply commands
https://github.com/babel/babel/security/advisories/GHSA-fv7c-fp4j-7gwp
OS impact
Debian Affected 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Affected | โ |
| sid | Affected | โ |
| forky | Affected | โ |
| bullseye | Affected | โ |
| bookworm | Affected | โ |
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| โ | Affected | โ |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| npm | @babel/plugin-transform-modules-systemjs | >=7.12.0,<7.29.4 | 7.29.4 |
| npm | @babel/plugin-transform-modules-systemjs | >=8.0.0-alpha.0,<8.0.0-alpha.13 | 8.0.0-alpha.13 |
| NPM | @babel/plugin-transform-modules-systemjs | >= 8.0.0-alpha.0, <= 8.0.0-alpha.12 | 8.0.0-alpha.13 |
| NPM | @babel/plugin-transform-modules-systemjs | >= 7.12.0, <= 7.29.3 | 7.29.4 |
References
CWEs
CWE-94 CWE-843
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.