{"id":"GHSA-4x5r-pxfx-6jf8","summary":"@babel/core: Arbitrary File Read via sourceMappingURL Comment","details":"## Impact\n\nUsing `@babel/core` to compile maliciously crafted code can allow ab attacker to read any source map from the system that is running Babel, if these conditions are _all_ true:\n- the attacker controls the input source code\n- the attacker can read the output source code\n- the attacker knows the path of the source map file that they want to read\n\n**Users that only compile trusted code are not impacted.**\n\n## Patches\n\nThe vulnerability has been fixed in `@babel/core@7.29.6` and `@babel/core@8.0.0-rc.6`.\n\n## Workarounds\n\nCallers can mitigate the issue without upgrading by setting [`inputSourceMap: false`](https://babeljs.io/docs/options#inputsourcemap) in their Babel options.\n\nCallers can also manually extract the `#sourceMappingURL` comment from the input source code, validate whether the source map that it links to is allowed to be read, and if it is pass an object to `inputSourceMap` (passing `false` when it's not).\n\n## Credits\n\nThanks Teodor-Cristian Radoi for reporting the vulnerability.","aliases":["CVE-2026-49356"],"modified":"2026-07-17T21:16:53.301599050Z","published":"2026-06-15T17:14:14Z","database_specific":{"nvd_published_at":"2026-06-22T18:16:41Z","cwe_ids":["CWE-200","CWE-22"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-06-15T17:14:14Z"},"references":[{"type":"WEB","url":"https://github.com/babel/babel/security/advisories/GHSA-4x5r-pxfx-6jf8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49356"},{"type":"WEB","url":"https://babeljs.io/docs/options#inputsourcemap"},{"type":"PACKAGE","url":"https://github.com/babel/babel"}],"affected":[{"package":{"name":"@babel/core","ecosystem":"npm","purl":"pkg:npm/%40babel/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.0.0-alpha.0"},{"fixed":"8.0.0-rc.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-4x5r-pxfx-6jf8/GHSA-4x5r-pxfx-6jf8.json","last_known_affected_version_range":"\u003c 8.0.0-rc.5"}},{"package":{"name":"@babel/core","ecosystem":"npm","purl":"pkg:npm/%40babel/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"7.29.6"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 7.29.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-4x5r-pxfx-6jf8/GHSA-4x5r-pxfx-6jf8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N"}]}