CVE-2023-45133
published 2023-10-12CVE-2023-45133: Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to…
PriorityP349high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.52%
41.3th percentile
Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the `path.evaluate()`or `path.evaluateTruthy()` internal Babel methods. Known affected plugins are `@babel/plugin-transform-runtime`; `@babel/preset-env` when using its `useBuiltIns` option; and any "polyfill provider" plugin that depends on `@babel/helper-define-polyfill-provider`, such as `babel-plugin-polyfill-corejs3`, `babel-plugin-polyfill-corejs2`, `babel-plugin-polyfill-es-shims`, `babel-plugin-polyfill-regenerator`. No other plugins under the `@babel/` namespace are impacted, but third-party plugins might be. Users that only compile trusted code are not impacted. The vulnerability has been fixed in `@babel/[email protected]` and `@babel/[email protected]`. Those who cannot upgrade `@babel/traverse` and are using one of the affected packages mentioned above should upgrade them to their latest version to avoid triggering the vulnerable code path in affected `@babel/traverse` versions: `@babel/plugin-transform-runtime` v7.23.2, `@babel/preset-env` v7.23.2, `@babel/helper-define-polyfill-provider` v0.4.3, `babel-plugin-polyfill-corejs2` v0.4.6, `babel-plugin-polyfill-corejs3` v0.8.5, `babel-plugin-polyfill-es-shims` v0.10.0, `babel-plugin-polyfill-regenerator` v0.5.3.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| babel | babel | < 7.23.2 | 7.23.2 |
| babel | babel | — | — |
| babel | traverse | >= 0 < 7.23.2 | 7.23.2 |
| babel | traverse | >= 8.0.0-alpha.0 < 8.0.0-alpha.4 | 8.0.0-alpha.4 |
| babeljs | babel | < 7.23.2 | 7.23.2 |
| babeljs | babel | — | — |
| babeljs | babel-helper-define-polyfill-provider | < 0.4.3 | 0.4.3 |
| babeljs | babel-plugin-polyfill-corejs2 | < 0.4.6 | 0.4.6 |
| babeljs | babel-plugin-polyfill-corejs3 | < 0.8.5 | 0.8.5 |
| babeljs | babel-plugin-polyfill-es-shims | < 0.10.0 | 0.10.0 |
| babeljs | babel-plugin-polyfill-regenerator | < 0.5.3 | 0.5.3 |
| babeljs | babel-plugin-transform-runtime | < 7.23.2 | 7.23.2 |
| babeljs | babel-preset-env | < 7.23.2 | 7.23.2 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | node-babel7 | < node-babel7 7.20.15+ds1+~cs214.269.168-3+deb12u1 (bookworm) | node-babel7 7.20.15+ds1+~cs214.269.168-3+deb12u1 (bookworm) |
| msrc | azl3_babel_2.12.1-1_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
osv8.8HIGH
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens COMOS
cisa_ics·2025-11-13·CVSS 9.3
[CRITICAL] Siemens COMOS
ICS Advisory
##
Siemens COMOS
Release DateNovember 13, 2025
Alert CodeICSA-25-317-15
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: COMOS
- Vulnerabilities: Incomplete List of Disallowed Inputs, Cleartext Transmission of Sensitive Information
## 2. RISK EVALUATION
Successf
Red Hat
babel: arbitrary code execution
vendor_redhat·2023-10-11·CVSS 9.3
CVE-2023-45133 [CRITICAL] CWE-184 babel: arbitrary code execution
babel: arbitrary code execution
Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the `path.evaluate()`or `path.evaluateTruthy()` internal Babel methods. Known affected plugins are `@babel/plugin-transform-runtime`; `@babel/preset-env` when using its `useBuiltIns` option; and any "polyfill provider" plugin that depends on `@babel/helper-define-polyfill-provider`, such as `babel-plugin-polyfill-corejs3`, `babel-plugin-polyfill-corejs2`, `babel-plugin-polyfill-es-shims`, `babel-plugin-polyfill-regenerator`. No other plugins under the `@ba
Microsoft
Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
vendor_msrc·2023-10-10·CVSS 8.8
CVE-2023-45133 [CRITICAL] CWE-184 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Debian
CVE-2023-45133: node-babel7 - Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to version...
vendor_debian·2023·CVSS 9.3
CVE-2023-45133 [CRITICAL] CVE-2023-45133: node-babel7 - Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to version...
Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the `path.evaluate()`or `path.evaluateTruthy()` internal Babel methods. Known affected plugins are `@babel/plugin-transform-runtime`; `@babel/preset-env` when using its `useBuiltIns` option; and any "polyfill provider" plugin that depends on `@babel/helper-define-polyfill-provider`, such as `babel-plugin-polyfill-corejs3`, `babel-plugin-polyfill-corejs2`, `babel-plugin-polyfill-es-shims`, `babel-plugin-polyfill-regenerator`. No other plugins under the `@babel/` namespace are impacted, but
GHSA
Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
ghsa·2023-10-16
CVE-2023-45133 [CRITICAL] CWE-184 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
### Impact
Using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the `path.evaluate()`or `path.evaluateTruthy()` internal Babel methods.
Known affected plugins are:
- `@babel/plugin-transform-runtime`
- `@babel/preset-env` when using its [`useBuiltIns`](https://babeljs.io/docs/babel-preset-env#usebuiltins) option
- Any "polyfill provider" plugin that depends on `@babel/helper-define-polyfill-provider`, such as `babel-plugin-polyfill-corejs3`, `babel-plugin-polyfill-corejs2`, `babel-plugin-polyfill-es-shims`, `babel-plugin-polyfill-regenerator`
No other plugins under the `@babel/` names
OSV
Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
osv·2023-10-16
CVE-2023-45133 [CRITICAL] Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
### Impact
Using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the `path.evaluate()`or `path.evaluateTruthy()` internal Babel methods.
Known affected plugins are:
- `@babel/plugin-transform-runtime`
- `@babel/preset-env` when using its [`useBuiltIns`](https://babeljs.io/docs/babel-preset-env#usebuiltins) option
- Any "polyfill provider" plugin that depends on `@babel/helper-define-polyfill-provider`, such as `babel-plugin-polyfill-corejs3`, `babel-plugin-polyfill-corejs2`, `babel-plugin-polyfill-es-shims`, `babel-plugin-polyfill-regenerator`
No other plugins under the `@babel/` names
OSV
CVE-2023-45133: Babel is a compiler for writingJavaScript
osv·2023-10-12·CVSS 8.8
CVE-2023-45133 [HIGH] CVE-2023-45133: Babel is a compiler for writingJavaScript
Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the `path.evaluate()`or `path.evaluateTruthy()` internal Babel methods. Known affected plugins are `@babel/plugin-transform-runtime`; `@babel/preset-env` when using its `useBuiltIns` option; and any "polyfill provider" plugin that depends on `@babel/helper-define-polyfill-provider`, such as `babel-plugin-polyfill-corejs3`, `babel-plugin-polyfill-corejs2`, `babel-plugin-polyfill-es-shims`, `babel-plugin-polyfill-regenerator`. No other plugins under the `@babel/` namespace are impacted, but
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/babel/babel/commit/b13376b346946e3f62fc0848c1d2a23223314c82https://github.com/babel/babel/pull/16033https://github.com/babel/babel/releases/tag/v7.23.2https://github.com/babel/babel/releases/tag/v8.0.0-alpha.4https://github.com/babel/babel/security/advisories/GHSA-67hx-6x53-jw92https://lists.debian.org/debian-lts-announce/2023/10/msg00026.htmlhttps://www.debian.org/security/2023/dsa-5528https://github.com/babel/babel/commit/b13376b346946e3f62fc0848c1d2a23223314c82https://github.com/babel/babel/pull/16033https://github.com/babel/babel/releases/tag/v7.23.2https://github.com/babel/babel/releases/tag/v8.0.0-alpha.4https://github.com/babel/babel/security/advisories/GHSA-67hx-6x53-jw92https://lists.debian.org/debian-lts-announce/2023/10/msg00026.htmlhttps://www.debian.org/security/2023/dsa-5528
2023-10-12
Published