Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-49356

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 3.6

Описание

Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the system that is running Babel, if the attacker controls the input source code, can read the output source code, and knows the path of the source map file that they want to read. This vulnerability is fixed in 8.0.0-rc.6 and 7.29.6.

A flaw was found in @babel/core. This vulnerability allows an attacker, who controls the input source code and can read the output, to perform an arbitrary file read. By compiling maliciously crafted code containing a sourceMappingURL comment, the attacker can read any source map file from the system where Babel is running, leading to information disclosure.

Отчет

Red Hat rates this issue as having Low impact for Red Hat AI products. @babel/core is bundled only in build-time or developer UI tooling (dashboard, model registry, MLflow) and the arbitrary file read requires local access and attacker-controlled source map processing that is not exposed in normal production use.

Меры по смягчению последствий

Do not process untrusted source maps with @babel/core in production services. Restrict access to developer UI components.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4coreNot affected
Cryostat 4cryostat-openshift-console-plugin-npmNot affected
Cryostat 4grafana-infinity-datasource-npmNot affected
Gatekeeper 3gatekeeper/gatekeeper-rhel9Not affected
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Not affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-must-gather-rhel9Not affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-operator-bundleNot affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel9-operatorNot affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-pf5-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2491445@babel/core: @babel/core: Arbitrary file read via sourceMappingURL comment

3.6 Low

CVSS3

Связанные уязвимости

CVSS3: 3.2
ubuntu
около 1 месяца назад

Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the system that is running Babel, if the attacker controls the input source code, can read the output source code, and knows the path of the source map file that they want to read. This vulnerability is fixed in 8.0.0-rc.6 and 7.29.6.

CVSS3: 3.2
nvd
около 1 месяца назад

Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the system that is running Babel, if the attacker controls the input source code, can read the output source code, and knows the path of the source map file that they want to read. This vulnerability is fixed in 8.0.0-rc.6 and 7.29.6.

msrc
около 1 месяца назад

Babel: Arbitrary File Read via sourceMappingURL Comment in @babel/core

CVSS3: 3.2
debian
около 1 месяца назад

Babel is a compiler for writing next generation JavaScript. Prior to 8 ...

CVSS3: 3.2
github
около 2 месяцев назад

@babel/core: Arbitrary File Read via sourceMappingURL Comment

3.6 Low

CVSS3