{"api_version":"1","generated_at":"2026-07-24T18:53:23+00:00","cve":"CVE-2023-45133","urls":{"html":"https://cve.report/CVE-2023-45133","api":"https://cve.report/api/cve/CVE-2023-45133.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-45133","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-45133"},"summary":{"title":"CVE-2023-45133","description":"Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the `path.evaluate()`or `path.evaluateTruthy()` internal Babel methods. Known affected plugins are `@babel/plugin-transform-runtime`; `@babel/preset-env` when using its `useBuiltIns` option; and any \"polyfill provider\" plugin that depends on `@babel/helper-define-polyfill-provider`, such as `babel-plugin-polyfill-corejs3`, `babel-plugin-polyfill-corejs2`, `babel-plugin-polyfill-es-shims`, `babel-plugin-polyfill-regenerator`. No other plugins under the `@babel/` namespace are impacted, but third-party plugins might be. Users that only compile trusted code are not impacted. The vulnerability has been fixed in `@babel/traverse@7.23.2` and `@babel/traverse@8.0.0-alpha.4`. Those who cannot upgrade `@babel/traverse` and are using one of the affected packages mentioned above should upgrade them to their latest version to avoid triggering the vulnerable code path in affected `@babel/traverse` versions: `@babel/plugin-transform-runtime` v7.23.2, `@babel/preset-env` v7.23.2, `@babel/helper-define-polyfill-provider` v0.4.3, `babel-plugin-polyfill-corejs2` v0.4.6, `babel-plugin-polyfill-corejs3` v0.8.5, `babel-plugin-polyfill-es-shims` v0.10.0, `babel-plugin-polyfill-regenerator` v0.5.3.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2023-10-12 17:15:00","updated_at":"2023-10-24 16:52:00"},"problem_types":["CWE-697"],"metrics":[],"references":[{"url":"https://github.com/babel/babel/security/advisories/GHSA-67hx-6x53-jw92","name":"https://github.com/babel/babel/security/advisories/GHSA-67hx-6x53-jw92","refsource":"MISC","tags":[],"title":"Arbitrary code execution when compiling specifically crafted malicious code · Advisory · babel/babel · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/babel/babel/releases/tag/v8.0.0-alpha.4","name":"https://github.com/babel/babel/releases/tag/v8.0.0-alpha.4","refsource":"MISC","tags":[],"title":"Release v8.0.0-alpha.4 · babel/babel · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/babel/babel/pull/16033","name":"https://github.com/babel/babel/pull/16033","refsource":"MISC","tags":[],"title":"Only evaluate own String/Number/Math methods by nicolo-ribaudo · Pull Request #16033 · babel/babel · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/babel/babel/commit/b13376b346946e3f62fc0848c1d2a23223314c82","name":"https://github.com/babel/babel/commit/b13376b346946e3f62fc0848c1d2a23223314c82","refsource":"MISC","tags":[],"title":"Only evaluate own String/Number/Math methods (#16033) · babel/babel@b13376b · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.debian.org/security/2023/dsa-5528","name":"https://www.debian.org/security/2023/dsa-5528","refsource":"MISC","tags":[],"title":"Debian -- Security Information -- DSA-5528-1 node-babel7","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/babel/babel/releases/tag/v7.23.2","name":"https://github.com/babel/babel/releases/tag/v7.23.2","refsource":"MISC","tags":[],"title":"Release v7.23.2 · babel/babel · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00026.html","name":"https://lists.debian.org/debian-lts-announce/2023/10/msg00026.html","refsource":"MISC","tags":[],"title":"[SECURITY] [DLA 3618-1] node-babel security update","mime":"text/html","httpstatus":"200","archivestatus":"429"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-45133","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45133","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"45133","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"babeljs","cpe5":"babel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"nodejs","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"45133","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"babeljs","cpe5":"babel","cpe6":"8.0.0","cpe7":"alpha.0","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"nodejs","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"45133","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"babeljs","cpe5":"babel","cpe6":"8.0.0","cpe7":"alpha.1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"nodejs","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"45133","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"babeljs","cpe5":"babel","cpe6":"8.0.0","cpe7":"alpha.2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"nodejs","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"45133","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"babeljs","cpe5":"babel","cpe6":"8.0.0","cpe7":"alpha.3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"nodejs","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"45133","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"babeljs","cpe5":"babel-helper-define-polyfill-provider","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"nodejs","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"45133","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"babeljs","cpe5":"babel-plugin-polyfill-corejs2","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"nodejs","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"45133","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"babeljs","cpe5":"babel-plugin-polyfill-corejs3","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"nodejs","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"45133","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"babeljs","cpe5":"babel-plugin-polyfill-es-shims","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"nodejs","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"45133","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"babeljs","cpe5":"babel-plugin-polyfill-regenerator","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"nodejs","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"45133","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"babeljs","cpe5":"babel-plugin-transform-runtime","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"nodejs","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"45133","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"babeljs","cpe5":"babel-preset-env","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"nodejs","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"45133","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"10.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"45133","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"11.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"45133","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"12.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2023-45133","qid":"6000259","title":"Debian Security Update for node-babel (DLA 3618-1)"},{"cve":"CVE-2023-45133","qid":"6000297","title":"Debian Security Update for node-babel7 (DSA 5528-1)"},{"cve":"CVE-2023-45133","qid":"995584","title":"NodeJs (Npm) Security Update for @babel/traverse (GHSA-67hx-6x53-jw92)"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-45133","ASSIGNER":"security-advisories@github.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the `path.evaluate()`or `path.evaluateTruthy()` internal Babel methods. Known affected plugins are `@babel/plugin-transform-runtime`; `@babel/preset-env` when using its `useBuiltIns` option; and any \"polyfill provider\" plugin that depends on `@babel/helper-define-polyfill-provider`, such as `babel-plugin-polyfill-corejs3`, `babel-plugin-polyfill-corejs2`, `babel-plugin-polyfill-es-shims`, `babel-plugin-polyfill-regenerator`. No other plugins under the `@babel/` namespace are impacted, but third-party plugins might be. Users that only compile trusted code are not impacted. The vulnerability has been fixed in `@babel/traverse@7.23.2` and `@babel/traverse@8.0.0-alpha.4`. Those who cannot upgrade `@babel/traverse` and are using one of the affected packages mentioned above should upgrade them to their latest version to avoid triggering the vulnerable code path in affected `@babel/traverse` versions: `@babel/plugin-transform-runtime` v7.23.2, `@babel/preset-env` v7.23.2, `@babel/helper-define-polyfill-provider` v0.4.3, `babel-plugin-polyfill-corejs2` v0.4.6, `babel-plugin-polyfill-corejs3` v0.8.5, `babel-plugin-polyfill-es-shims` v0.10.0, `babel-plugin-polyfill-regenerator` v0.5.3."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-184: Incomplete List of Disallowed Inputs","cweId":"CWE-184"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"babel","product":{"product_data":[{"product_name":"babel","version":{"version_data":[{"version_affected":"=","version_value":"< 7.23.2"},{"version_affected":"=","version_value":">= 8.0.0-alpha.0, < 8.0.0-alpha.4"}]}}]}}]}},"references":{"reference_data":[{"url":"https://github.com/babel/babel/security/advisories/GHSA-67hx-6x53-jw92","refsource":"MISC","name":"https://github.com/babel/babel/security/advisories/GHSA-67hx-6x53-jw92"},{"url":"https://github.com/babel/babel/pull/16033","refsource":"MISC","name":"https://github.com/babel/babel/pull/16033"},{"url":"https://github.com/babel/babel/commit/b13376b346946e3f62fc0848c1d2a23223314c82","refsource":"MISC","name":"https://github.com/babel/babel/commit/b13376b346946e3f62fc0848c1d2a23223314c82"},{"url":"https://github.com/babel/babel/releases/tag/v7.23.2","refsource":"MISC","name":"https://github.com/babel/babel/releases/tag/v7.23.2"},{"url":"https://github.com/babel/babel/releases/tag/v8.0.0-alpha.4","refsource":"MISC","name":"https://github.com/babel/babel/releases/tag/v8.0.0-alpha.4"},{"url":"https://www.debian.org/security/2023/dsa-5528","refsource":"MISC","name":"https://www.debian.org/security/2023/dsa-5528"},{"url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00026.html","refsource":"MISC","name":"https://lists.debian.org/debian-lts-announce/2023/10/msg00026.html"}]},"source":{"advisory":"GHSA-67hx-6x53-jw92","discovery":"UNKNOWN"},"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":9.4,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}]}},"nvd":{"publishedDate":"2023-10-12 17:15:00","lastModifiedDate":"2023-10-24 16:52:00","problem_types":["CWE-697"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2,"impactScore":6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:babeljs:babel:8.0.0:alpha.1:*:*:*:nodejs:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:babeljs:babel:8.0.0:alpha.2:*:*:*:nodejs:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:babeljs:babel:8.0.0:alpha.3:*:*:*:nodejs:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:babeljs:babel:8.0.0:alpha.0:*:*:*:nodejs:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:babeljs:babel:*:*:*:*:*:nodejs:*:*","versionEndExcluding":"7.23.2","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:babeljs:babel-plugin-polyfill-regenerator:*:*:*:*:*:nodejs:*:*","versionEndExcluding":"0.5.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:babeljs:babel-plugin-polyfill-es-shims:*:*:*:*:*:nodejs:*:*","versionEndExcluding":"0.10.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:babeljs:babel-plugin-polyfill-corejs3:*:*:*:*:*:nodejs:*:*","versionEndExcluding":"0.8.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:babeljs:babel-plugin-polyfill-corejs2:*:*:*:*:*:nodejs:*:*","versionEndExcluding":"0.4.6","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:babeljs:babel-helper-define-polyfill-provider:*:*:*:*:*:nodejs:*:*","versionEndExcluding":"0.4.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:babeljs:babel-preset-env:*:*:*:*:*:nodejs:*:*","versionEndExcluding":"7.23.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:babeljs:babel-plugin-transform-runtime:*:*:*:*:*:nodejs:*:*","versionEndExcluding":"7.23.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}