Executive brief
Babel is a widely-used JavaScript compiler that transforms code to enable compatibility across different environments. When Babel compiles malicious code crafted by an attacker, it can execute arbitrary commands during the compilation process if certain plugins are enabled. This allows an attacker to gain code execution on any developer's machine that compiles untrusted code, potentially compromising the development environment and deployed applications.
Technical details
The vulnerability exists in @babel/traverse, which implements unsafe evaluation methods (path.evaluate() and path.evaluateTruthy()) that do not properly restrict code execution during AST analysis. When plugins like @babel/plugin-transform-runtime, @babel/preset-env (with useBuiltIns), or polyfill provider plugins use these methods to analyze code, they can be tricked into executing attacker-supplied code. The attack requires local file system access to the babel compilation process and no user privileges, but the attacker must supply malicious code to be compiled. The vulnerability was fixed in @babel/traverse v7.23.2 and v8.0.0-alpha.4; Babel 6 does not receive security updates.
Affected products
- Babel @babel/traverse <7.23.2, 8.0.0-alpha.0 to 8.0.0-alpha.3
- Babel @babel/plugin-transform-runtime <7.23.2
- Babel @babel/preset-env <7.23.2
- Babel @babel/helper-define-polyfill-provider <0.4.3
- Babel babel-plugin-polyfill-corejs3 <0.8.5
- Babel babel-plugin-polyfill-corejs2 <0.4.6
- Babel babel-plugin-polyfill-es-shims <0.10.0
- Babel babel-plugin-polyfill-regenerator <0.5.3
Timeline
- 2023-10-12: disclosed: CVE-2023-45133 published
- 2023-10-16: advisory: GHSA-67hx-6x53-jw92 published
- 2023-10-16: patched: @babel/traverse 7.23.2 and 8.0.0-alpha.4 released