CVE-2026-44728: Babel
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13.
Affected products
- Babel Babel: from 7.12.0, before 7.29.4 (fixed in 7.29.4); version 8.0.0 only
Published 2026-05-26. Last modified 2026-07-24.