CVE-2026-49356Low· 3.2▾ Sunlit@babel/core: Arbitrary File Read via sourceMappingURL Comment
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.1%
0.1% → 0.1%
Using @babel/core to compile maliciously crafted code can allow ab attacker to read any source map from the system that is running Babel, if these conditions are all true:
Users that only compile trusted code are not impacted.
The vulnerability has been fixed in @babel/[email protected] and @babel/[email protected].
Callers can mitigate the issue without upgrading by setting inputSourceMap: false in their Babel options.
Callers can also manually extract the #sourceMappingURL comment from the input source code, validate whether the source map that it links to is allowed to be read, and if it is pass an object to inputSourceMap (passing false when it's not).
Thanks Teodor-Cristian Radoi for reporting the vulnerability.
@babel/core >= 8.0.0-alpha.0, < 8.0.0-rc.5@babel/core <= 7.29.0Upgrade to a patched release:
@babel/core 8.0.0-rc.6@babel/core 7.29.6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-45623High· 7.5postcss: PostCSS: Information disclosure and denial of service via crafted CSS input (CVE-2026-45623)
CVE-2021-25122High· 7.5When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning u…
CVE-2022-31746Medium· 6.5Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header
CVE-2026-47735HighArc is an open, SQL-native time-series database for telemetry
CVE-2026-49742HighTYPO3 CMS has Broken Access Control in its Media Module
CVE-2026-49219Medium· 5.5ImageMagick: Policy Bypass can read disallowed files via symlink