npm package report

Is @babel/plugin-transform-modules-systemjs safe?

1 known vulnerability, worst severity HIGH.

cvss
8.2

how bad it is if exploited, out of 10

epss
0.10%

chance of exploitation in the next 30 days

xyz score
4.3

CyberXYZ composite, out of 10

fig. 01 — GHSA-fv7c-fp4j-7gwp, the advisory selected below

// advisories

GHSA-fv7c-fp4j-7gwp

HIGHCVE-2026-44728

Using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code.

Affected
>=7.12.0, <7.29.4, >= 7.12.0, <= 7.29.3
Fixed in
7.29.4
Weakness
CWE-843
Published
2026-05-08
Source
osv

NVDMITREOSV


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 01:39 UTC. The most recent advisory here was published 2026-05-08. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @babel/plugin-transform-modules-systemjs safe? npm package security report | CyberXYZ