StackRadar

CVE-2026-49356

Low

Advisory

Published 15 Jun 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.2
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
184
of 17,781 indexed, latest versions
Container images
184
deployed by those charts
Fix available
1 of 1
affected package

@babel/core: Arbitrary File Read via sourceMappingURL Comment

Carried by container images the latest versions of 184 of 17,781 indexed charts deploy, on 184 images.

Affected packageAffected versionsFixed inImages
@babel/corenpm7.1.0, 7.1.2, 7.5.5, 7.7.2+69 more7.29.6184
OSV records
GHSA-4x5r-pxfx-6jf8

Charts affected

184 by stars
ChartLatestAffected imagesRadar Score
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
kitware/cdash:v5.3.0d7767d9b9da4
@babel/core@7.23.3
7.29.6

Open the chart page →

12,062
visual-regression-trackerkokuwa5.1.01 of 4See more

visual-regression-tracker kokuwa 5.1.0

1 of the 4 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
visualregressiontracker/api:5.0.11941aeb8c8bf9
@babel/core@7.22.20
7.29.6

Open the chart page →

9,098
rtlkronkltdVerified publisher0.1.01 of 2See more

rtl kronkltd 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
shahanafarooqui/rtl:0.11.0d0cd3d868aca
@babel/core@7.14.6
7.29.6

Open the chart page →

5,604
pangolinkrzwiatrzyk0.11.01 of 1See more

pangolin krzwiatrzyk 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
fosrl/pangolin:1.13.0c32ad797ab96
@babel/core@7.26.10
7.29.6

Open the chart page →

3,441
seerrkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

seerr kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
@babel/core@7.28.6
7.29.6

Open the chart page →

2,548
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
@babel/core@7.23.0
7.29.6

Open the chart page →

2,685
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
@babel/core@7.28.0
7.29.6

Open the chart page →

3,555
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
@babel/core@7.5.5
7.29.6

Open the chart page →

7,929
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
@babel/core@7.9.6
7.29.6

Open the chart page →

3,651
lynxpromptlynxpromptVerified publisher0.1.21 of 3See more

lynxprompt lynxprompt 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
drumsergio/lynxprompt:2.0.75c6afb6679301
@babel/core@7.29.0
7.29.6

Open the chart page →

1,852
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
@babel/core@7.23.9
7.29.6

Open the chart page →

4,647
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/rodg/nodecg-base:latest31be4bf87070
@babel/core@7.24.4
7.29.6

Open the chart page →

7,315
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
@babel/core@7.14.6
7.29.6

Open the chart page →

5,287
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
@babel/core@7.28.6
7.29.6

Open the chart page →

8,303
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
@babel/core@7.14.0
7.29.6

Open the chart page →

5,940
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
@babel/core@7.27.4
7.29.6

Open the chart page →

43,341
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
@babel/core@7.23.7
7.29.6

Open the chart page →

14,809
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
@babel/core@7.23.7
7.29.6

Open the chart page →

2,316
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
library/mongo-express:latest1b23d7976f02
@babel/core@7.19.6
7.29.6

Open the chart page →

5,179
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
@babel/core@7.12.3
7.29.6

Open the chart page →

6,438
api-proxymoreillonVerified publisher0.1.41 of 1See more

api-proxy moreillon 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
moreillon/api-proxy:2373c1953739ef6956b5
@babel/core@7.21.0
7.29.6

Open the chart page →

1,712
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
@babel/core@7.18.2
7.29.6

Open the chart page →

8,556
group-managermoreillonVerified publisher0.4.41 of 3See more

group-manager moreillon 0.4.4

1 of the 3 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
moreillon/group-manager:v4.9.0d5a0ec8394c0
@babel/core@7.22.20
7.29.6

Open the chart page →

9,835
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
@babel/core@7.23.5
7.29.6

Open the chart page →

25,704
user-manager-neo4jmoreillonVerified publisher0.9.72 of 6See more

user-manager-neo4j moreillon 0.9.7

2 of the 6 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
moreillon/group-manager:v4.9.0d5a0ec8394c0
@babel/core@7.22.20
7.29.6
moreillon/user-manager:v5.0.2e1c9bfab5c16
@babel/core@7.20.12
7.29.6

Open the chart page →

30,363
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
@babel/core@7.10.5
7.29.6

Open the chart page →

6,684
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
@babel/core@7.20.12
7.29.6

Open the chart page →

6,608
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
@babel/core@7.19.6
7.29.6

Open the chart page →

3,128
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
@babel/core@7.21.4
7.29.6

Open the chart page →

2,116
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
@babel/core@7.21.4
7.29.6

Open the chart page →

2,116
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
@babel/core@7.21.4
7.29.6

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
@babel/core@7.21.4
7.29.6

Open the chart page →

2,116
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
@babel/core@7.21.4
7.29.6

Open the chart page →

17,929
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
@babel/core@7.17.0
7.29.6

Open the chart page →

3,269
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
@babel/core@7.29.0
7.29.6

Open the chart page →

3,798
node-appnode-app-lili1.0.01 of 1See more

node-app node-app-lili 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
laly9999/node-app:1dd0e503913e1
@babel/core@7.27.3
7.29.6

Open the chart page →

10,218
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
@babel/core@7.22.9
7.29.6

Open the chart page →

15,132
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
@babel/core@7.22.8
7.29.6

Open the chart page →

15,206
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
@babel/core@7.21.0
7.29.6

Open the chart page →

15,187
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
@babel/core@7.15.5
7.29.6

Open the chart page →

9,968
kratos-selfservice-ui-noderadar-baseVerified publisher0.43.11 of 1See more

kratos-selfservice-ui-node radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
@babel/core@7.17.8
7.29.6

Open the chart page →

2,969
recipe-apprecipe-app0.1.02 of 2See more

recipe-app recipe-app 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
@babel/core@7.25.2
7.29.6
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
@babel/core@7.25.2
7.29.6

Open the chart page →

3,271
helm-redchefredchef0.1.01 of 3See more

helm-redchef redchef 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
sharanalwar/redchef-frontend:latest5e82950b16b7
@babel/core@7.26.10
7.29.6

Open the chart page →

4,763
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
@babel/core@7.23.6
7.29.6

Open the chart page →

6,282
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
@babel/core@7.25.2
7.29.6

Open the chart page →

7,084
mastodonrivals-spaceVerified publisher3.1.21 of 3See more

mastodon rivals-space 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
@babel/core@7.20.12
7.29.6

Open the chart page →

6,026
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
@babel/core@7.22.5
7.29.6

Open the chart page →

7,413
samplesample0.1.01 of 2See more

sample sample 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
library/mongo-express:1.0.2-20-alpine3.191aae00775251
@babel/core@7.19.6
7.29.6

Open the chart page →

2,309
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
@babel/core@7.21.0
7.29.6

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
@babel/core@7.15.8
7.29.6

Open the chart page →

3,638

Container images carrying it

184 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
@babel/core@7.1.2
7.29.6
1
fosrl/pangolin:1.13.0c32ad797ab96
@babel/core@7.26.10
7.29.6
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
@babel/core@7.21.4
7.29.6
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
@babel/core@7.21.8
7.29.6
1
henrywhitaker3/speedtest-tracker:latest47159a940229
@babel/core@7.12.3
7.29.6
1
heywood8/redisinsight:2.28.00bc9ab313d37
@babel/core@7.21.4
7.29.6
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
@babel/core@7.16.7
7.29.6
1
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
@babel/core@7.26.10
7.29.6
1
joplin/server:3.0-beta52af57880c0e
@babel/core@7.22.5
7.29.6
1
joplin/server:2.14.2-betab87564ef34e9
@babel/core@7.22.5
7.29.6
1
junktext/getting-started:1.0.5a70936c04aed
@babel/core@7.15.8
7.29.6
1
junktext/getting-started:1.0.34d44adf5a4da2
@babel/core@7.15.8
7.29.6
1
jupyterhub/jupyterhub:5.4.63974ba945e65
@babel/core@7.20.12
7.29.6
1
keyoxide/keyoxide:stable96f27a71269d
@babel/core@7.17.7
7.29.6
1
kitware/cdash:v5.3.0d7767d9b9da4
@babel/core@7.23.3
7.29.6
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
@babel/core@7.17.9
7.29.6
1
kyleslugg/klusterview:latestba8c36dfdfbd
@babel/core@7.22.5
7.29.6
1
kyso/kyso-front:lateste52595c5c16f
@babel/core@7.23.0
7.29.6
1
laly9999/node-app:1dd0e503913e1
@babel/core@7.27.3
7.29.6
1
lavandadelpatio/frontend:latest501c3f31e0bc
@babel/core@7.9.6
7.29.6
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
@babel/core@7.25.2
7.29.6
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
@babel/core@7.19.6
7.29.6
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
@babel/core@7.14.5
7.29.6
1
linuxserver/overseerr:1.35.06108ed066d4a
@babel/core@7.20.7
7.29.6
1
lissy93/dashy:2.0.51991f7be5ed0
@babel/core@7.17.0
7.29.6
1
mautic/mautic:7-apacheeb8cc73d97e1
@babel/core@7.28.6
7.29.6
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
@babel/core@7.27.4
7.29.6
1
misskey/misskey:12.110.1e08b7c478093
@babel/core@7.11.4
7.29.6
1
mitchxxx/amazon:214e72480ec63a
@babel/core@7.21.4
7.29.6
1
moreillon/api-proxy:2373c1953739ef6956b5
@babel/core@7.21.0
7.29.6
1
moreillon/api-proxy:latestd7d4a5463525
@babel/core@7.21.0
7.29.6
1
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
@babel/core@7.18.2
7.29.6
1
moreillon/food-manager:lateste8fd856e593d
@babel/core@7.25.2
7.29.6
1
moreillon/group-manager:latest3caa8f710ee0
@babel/core@7.25.2
7.29.6
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
@babel/core@7.23.5
7.29.6
1
mozilla/sentencecollector:2.0.91da6ff5c4895
@babel/core@7.10.5
7.29.6
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
@babel/core@7.11.4
7.29.6
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
@babel/core@7.20.12
7.29.6
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
@babel/core@7.20.12
7.29.6
1
nocodb/nocodb:0.301.5d9516f0bf546
@babel/core@7.29.0
7.29.6
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
@babel/core@7.28.5
7.29.6
1
ondrejsika/parking:latestb1fd497416c8
@babel/core@7.7.2
7.29.6
1
ooghenekaro/amazon:latest03394ba1d6d8
@babel/core@7.21.4
7.29.6
1
openbas/caldera-server:5.1.0a277796d9724
@babel/core@7.18.2
7.29.6
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
@babel/core@7.19.3
7.29.6
1
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
@babel/core@7.17.8
7.29.6
1
outlinewiki/outline:0.82.0494dfb9249a6
@babel/core@7.26.7
7.29.6
1
pysga1996/python-redis-web:latestfdeec30ad482
@babel/core@7.12.16
7.29.6
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
@babel/core@7.26.8
7.29.6
1
requarks/wiki:canary-2.5.2438b5865a7386c
@babel/core@7.15.8
7.29.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.