Junglewise Threat Intelligence

CVE-2023-45133: Babel arbitrary code execution in code compilation

CVE-2023-45133 · Severity: low · CVSS 3.1 · Published 2023-10-16

Executive brief

Babel is a widely-used JavaScript compiler that transforms code to enable compatibility across different environments. When Babel compiles malicious code crafted by an attacker, it can execute arbitrary commands during the compilation process if certain plugins are enabled. This allows an attacker to gain code execution on any developer's machine that compiles untrusted code, potentially compromising the development environment and deployed applications.

Technical details

The vulnerability exists in @babel/traverse, which implements unsafe evaluation methods (path.evaluate() and path.evaluateTruthy()) that do not properly restrict code execution during AST analysis. When plugins like @babel/plugin-transform-runtime, @babel/preset-env (with useBuiltIns), or polyfill provider plugins use these methods to analyze code, they can be tricked into executing attacker-supplied code. The attack requires local file system access to the babel compilation process and no user privileges, but the attacker must supply malicious code to be compiled. The vulnerability was fixed in @babel/traverse v7.23.2 and v8.0.0-alpha.4; Babel 6 does not receive security updates.

Affected products

  • Babel @babel/traverse <7.23.2, 8.0.0-alpha.0 to 8.0.0-alpha.3
  • Babel @babel/plugin-transform-runtime <7.23.2
  • Babel @babel/preset-env <7.23.2
  • Babel @babel/helper-define-polyfill-provider <0.4.3
  • Babel babel-plugin-polyfill-corejs3 <0.8.5
  • Babel babel-plugin-polyfill-corejs2 <0.4.6
  • Babel babel-plugin-polyfill-es-shims <0.10.0
  • Babel babel-plugin-polyfill-regenerator <0.5.3

Timeline

  • 2023-10-12: disclosed: CVE-2023-45133 published
  • 2023-10-16: advisory: GHSA-67hx-6x53-jw92 published
  • 2023-10-16: patched: @babel/traverse 7.23.2 and 8.0.0-alpha.4 released

References