QID 995584
Date Published: 2023-10-17
QID 995584: NodeJs (Npm) Security Update for @babel/traverse (GHSA-67hx-6x53-jw92)
Using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the path.evaluate()or path.evaluateTruthy() internal Babel methods.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-67hx-6x53-jw92 for updates and patch information.
Vendor References
- GHSA-67hx-6x53-jw92 -
github.com/advisories/GHSA-67hx-6x53-jw92
CVEs related to QID 995584
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-67hx-6x53-jw92 | @babel/traverse |
|