CVE-2026-49356Disclosure(babel / babel)

LOWCVSS 3.6 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the system that is running Babel, if the attacker controls the input source code, can read the output source code, and knows the path of the source map file that they want to read. This vulnerability is fixed in 8.0.0-rc.6 and 7.29.6.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • babel

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-15); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
babel

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-15: 1Mentions · 2026-06-18: 1Technical Details · 2026-06-15: 106-1506-18
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-151
Disclosure1
2026-06-181
General1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-49356 Par Term Emu Core Rust A comprehensive terminal emulator library written in Rust with Python bindings for Python 3.12+. Provides VT100/VT220/VT320/VT420/VT520 compatibility with PTY support,... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-49356

    Post summary

    The text identifies CVE-2026-49356 for the Par Term Emu Core Rust library but offers no substantive technical details, PoC, exploit code, or patch information.

    0000051
    4.1K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔵 #CVE-2026-49356: Arbitrary File Read via SourceMappingURL Comment -DC-Jun2026-412 https://dailycve.com/cve-2026-49356-arbitrary-file-read-via-sourcemappingurl-comment-dc-jun2026-412/

    Post summary

    DailyCVE has announced CVE‑2026‑49356, a file‑read vulnerability triggered by a SourceMappingURL comment, providing basic technical details but no PoC, exploit, or patch information.

    0000034
    212 followersView on X
CPE platform detail29 entries

29 of 29 entries

PartVendorProductVersionTarget SWTarget HW
Appbabelbabel---
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--
Appbabelbabel8.0.0--

Explore more