CVE-2023-45133 is an arbitrary code execution vulnerability in Babel's @babel/traverse component, affecting Babel versions prior to 7.23.2 and 8.0.0-alpha.4, as well as specific plugins like @babel/plugin-transform-runtime and @babel/preset-env. An attacker can craft malicious JavaScript code that, when compiled by Babel using vulnerable plugins, leads to arbitrary code execution during the compilation process. This vulnerability carries a high severity CVSS score of 8.8, indicating a significant risk. The attack vector is local, requiring the attacker to provide specially crafted code for compilation, but the impact includes high confidentiality, integrity, and availability compromise. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. However, the vulnerability has garnered community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* | ||
< 7.23.2CPE matchmatch criteria | cpe:2.3:a:babeljs:babel:*:*:*:*:*:nodejs:*:* | ||
8.0.0CPE matchmatch criteria | cpe:2.3:a:babeljs:babel:8.0.0:alpha.0:*:*:*:nodejs:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Splunk Enterprise Security (ES) Third-Party Package Updates - January 2024
Jan 9, 2024Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
Oct 16, 2023babel: arbitrary code execution
Oct 11, 2023Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
Oct 10, 2023