Home

Description

Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13.

PUBLISHED Reserved 2026-05-07 | Published 2026-05-26 | Updated 2026-05-28 | Assigner GitHub_M




HIGH: 8.2CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Problem types

CWE-94: Improper Control of Generation of Code ('Code Injection')

CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')

Product status

>= 7.12.0, < 7.29.4
affected

>= 8.0.0-alpha.0, < 8.0.0-alpha.13
affected

>= 7.12.0, < 7.29.4
affected

>= 8.0.0-alpha.0, < 8.0.0-alpha.13
affected

References

github.com/.../babel/security/advisories/GHSA-fv7c-fp4j-7gwp

cve.org (CVE-2026-44728)

nvd.nist.gov (CVE-2026-44728)

Download JSON