Code Injection in babel - CVE-2026-44728

 

Code Injection in babel - CVE-2026-44728

Published: September 16, 2026


Vulnerability identifier: #VU150181
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44728
CWE-ID: CWE-94
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to improper control of code generation in @babel/plugin-transform-modules-systemjs when compiling specifically crafted malicious code. A local user can compile specifically crafted malicious code to execute arbitrary code.

User interaction is required.


Affected software

babel
Jira Software Data Center
Jira Service Management Data Center

How to mitigate CVE-2026-44728

Install security update from vendor's website.

babel - addressed in versions 7.29.4, 8.0.0 alpha.13
Jira Software Data Center - addressed in versions 10.3.23, 11.3.11
Jira Service Management Data Center - addressed in versions 10.3.23, 11.3.10

External References

Related Security Bulletins