CVE-2026-49356: Babel: Arbitrary File Read via sourceMappingURL Comment in @babel/core

Published Jun 15, 2026
·
Updated

Impact

Using @babel/core to compile maliciously crafted code can allow ab attacker to read any source map from the system that is running Babel, if these conditions are all true: - the attacker controls the input source code - the attacker can read the output source code - the attacker knows the path of the source map file that they want to read

Users that only compile trusted code are not impacted.

Patches

The vulnerability has been fixed in @babel/core@7.29.6 and @babel/core@8.0.0-rc.6.

Workarounds

Callers can mitigate the issue without upgrading by setting inputSourceMap: false in their Babel options.

Callers can also manually extract the #sourceMappingURL comment from the input source code, validate whether the source map that it links to is allowed to be read, and if it is pass an object to inputSourceMap (passing false when it's not).

Credits

Thanks Teodor-Cristian Radoi for reporting the vulnerability.

Other sources

Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the system that is running Babel, if the attacker controls the input source code, can read the output source code, and knows the path of the source map file that they want to read. This vulnerability is fixed in 8.0.0-rc.6 and 7.29.6.

MITRE

Affected Software

31 affected componentsFixes available
npm/@babel/core<=7.29.0
7.29.6
npm/@babel/core>=8.0.0-alpha.0<8.0.0-rc.5
8.0.0-rc.6
Babel Babel<7.29.6
Babel Babel=8.0.0-alpha0
Babel Babel=8.0.0-alpha1
Babel Babel=8.0.0-alpha10
Babel Babel=8.0.0-alpha11
Babel Babel=8.0.0-alpha12
Babel Babel=8.0.0-alpha13
Babel Babel=8.0.0-alpha14
Babel Babel=8.0.0-alpha15
Babel Babel=8.0.0-alpha16
Babel Babel=8.0.0-alpha17
Babel Babel=8.0.0-alpha2
Babel Babel=8.0.0-alpha3
Babel Babel=8.0.0-alpha4
Babel Babel=8.0.0-alpha5
Babel Babel=8.0.0-alpha6
Babel Babel=8.0.0-alpha7
Babel Babel=8.0.0-alpha8
Babel Babel=8.0.0-alpha9
Babel Babel=8.0.0-beta0
Babel Babel=8.0.0-beta1
Babel Babel=8.0.0-beta2
Babel Babel=8.0.0-beta3
Babel Babel=8.0.0-beta4
Babel Babel=8.0.0-rc1
Babel Babel=8.0.0-rc2
Babel Babel=8.0.0-rc3
Babel Babel=8.0.0-rc4
Babel Babel=8.0.0-rc5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@babel/core to a version that resolves this vulnerability.

    Fixed in 7.29.6
  2. Upgrade

    Upgrade npm/@babel/core to a version that resolves this vulnerability.

    Fixed in 8.0.0-rc.6
  3. Upgrade

    Upgrade @babel/core to a version that resolves this vulnerability.

    Fixed in 7.29.6
  4. Upgrade

    Upgrade @babel/core to a version that resolves this vulnerability.

    Fixed in 8.0.0-rc.6
  5. Configuration

    Set Babel option `inputSourceMap: false` to mitigate arbitrary file read via `sourceMappingURL` comment when not upgrading.

    @babel/core inputSourceMap = false

Event History

Jun 15, 2026
Advisory Published
via GitHub·05:14 PM
Data Sourced
via GitHub·05:14 PM
DescriptionSeverityWeaknessAffected Software
Jun 22, 2026
CVE Published
via MITRE·04:07 PM
Data Sourced
via MITRE·04:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-49356?

The severity of CVE-2026-49356 is classified as low, with a score of 3.2.

2

What is the impact of CVE-2026-49356?

CVE-2026-49356 can allow an attacker to read source maps from the system running Babel if they control the input source code and can read the output.

3

How do I fix CVE-2026-49356?

To fix CVE-2026-49356, ensure that your version of @babel/core is updated to the latest patched version.

4

What is a possible attack vector for CVE-2026-49356?

The attack vector for CVE-2026-49356 involves an attacker supplying malicious input source code that can exploit path traversal to access sensitive data.

5

Which software is affected by CVE-2026-49356?

The affected software for CVE-2026-49356 is npm/@babel/core.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203