Vulnerability library
Security checkJuly 15, 2026

@babel/core: Arbitrary File Read via sourceMappingURL Comment

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Low severitynpm@babel/core

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Using @babel/core to compile maliciously crafted code can allow ab attacker to read any source map from the system that is running Babel, if these conditions are all true:

  • the attacker controls the input source code
  • the attacker can read the output source code
  • the attacker knows the path of the source map file that they want to read

**Us

Recommendation

Update the @babel/core package to the latest compatible version. Followings are version details:

  • Affected version(s): **<= 7.29.0 >= 8.0.0-alpha.0, < 8.0.0-rc.5**
  • Patched version(s): **7.29.6 8.0.0-rc.6**

References

Could your website be exposed too?

SmartScanner can check your website for @babel/core: Arbitrary File Read via sourceMappingURL Comment and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 15, 2026