{"id":"GHSA-fv7c-fp4j-7gwp","summary":"@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input","details":"### Impact\n\nUsing Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code.\n\nKnown affected plugins are:\n- `@babel/plugin-transform-modules-systemjs`\n- `@babel/preset-env` when using the [`modules: \"systemjs\"` option](https://babel.dev/docs/babel-preset-env#modules), as it delegates to `@babel/plugin-transform-modules-systemjs`\n\nNo other plugins under the `@babel` namespace are impacted.\n\n**Users that only compile trusted code are not impacted.**\n\n### Patches\n\nThe vulnerability has been fixed in `@babel/plugin-transform-modules-systemjs@7.29.4`.\n\nBabel also released `@babel/preset-env@7.29.5`, updating its `@babel/plugin-transform-modules-systemjs` dependency, to simplify forcing the update if you are using `@babel/preset-env` directly.\n\n### Workarounds\n\n- Pin `@babel/parser` to v7.11.5. The downgrade will completely disable string module name parsing, but it would also disable other new language features and the build pipeline may fail as a result. Only do so if you are working on a legacy codebase and can not upgrade `@babel/plugin-transform-modules-systemjs` to v7.29.4.\n- Do not use the `modules: \"systemjs\"` option, migrate the codebase to native ES Modules or any other module formats.\n\n### Credits\nBabel thanks Daniel Cervera for reporting the vulnerability.","aliases":["CVE-2026-44728"],"modified":"2026-08-24T00:36:48.395276139Z","published":"2026-05-08T20:34:07Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-08T20:34:07Z","nvd_published_at":"2026-05-26T18:16:50Z","cwe_ids":["CWE-843","CWE-94"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/babel/babel/security/advisories/GHSA-fv7c-fp4j-7gwp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44728"},{"type":"PACKAGE","url":"https://github.com/babel/babel"}],"affected":[{"package":{"name":"@babel/plugin-transform-modules-systemjs","ecosystem":"npm","purl":"pkg:npm/%40babel/plugin-transform-modules-systemjs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.12.0"},{"fixed":"7.29.4"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 7.29.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fv7c-fp4j-7gwp/GHSA-fv7c-fp4j-7gwp.json"}},{"package":{"name":"@babel/plugin-transform-modules-systemjs","ecosystem":"npm","purl":"pkg:npm/%40babel/plugin-transform-modules-systemjs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.0.0-alpha.0"},{"fixed":"8.0.0-alpha.13"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 8.0.0-alpha.12","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fv7c-fp4j-7gwp/GHSA-fv7c-fp4j-7gwp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"}]}