Code Injection in babel - CVE-2026-44728
Published: September 16, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to improper control of code generation in @babel/plugin-transform-modules-systemjs when compiling specifically crafted malicious code. A local user can compile specifically crafted malicious code to execute arbitrary code.
User interaction is required.
Affected software
Jira Software Data Center
Jira Service Management Data Center
How to mitigate CVE-2026-44728
Jira Software Data Center - addressed in versions 10.3.23, 11.3.11
Jira Service Management Data Center - addressed in versions 10.3.23, 11.3.10