StackRadar

CVE-2026-49356

Low

Advisory

Published 15 Jun 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.2
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
184
of 17,781 indexed, latest versions
Container images
184
deployed by those charts
Fix available
1 of 1
affected package

@babel/core: Arbitrary File Read via sourceMappingURL Comment

Carried by container images the latest versions of 184 of 17,781 indexed charts deploy, on 184 images.

Affected packageAffected versionsFixed inImages
@babel/corenpm7.1.0, 7.1.2, 7.5.5, 7.7.2+69 more7.29.6184
OSV records
GHSA-4x5r-pxfx-6jf8

Charts affected

184 by stars
ChartLatestAffected imagesRadar Score
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
@babel/core@7.25.2
7.29.6

Open the chart page →

12,581
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
@babel/core@7.29.0
7.29.6

Open the chart page →

3,833
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
@babel/core@7.24.4
7.29.6

Open the chart page →

4,880
openhab-cloudandibraeuVerified publisher1.2.61 of 1See more

openhab-cloud andibraeu 1.2.6

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
openhab/openhab-cloud:a8138a329dd2bac8c4b
@babel/core@7.19.3
7.29.6

Open the chart page →

3,437
apimap-developerapimapOfficialVerified publisher1.4.11 of 1See more

apimap-developer apimap 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
apimap/developer:v1.3.1406d3858e20c
@babel/core@7.18.13
7.29.6

Open the chart page →

2,353
apimap-portalapimapOfficialVerified publisher2.4.01 of 1See more

apimap-portal apimap 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
apimap/portal:v2.4.0041a4790c65c
@babel/core@7.17.5
7.29.6

Open the chart page →

2,396
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:api-latest7473d77448e1
@babel/core@7.24.5
7.29.6

Open the chart page →

9,369
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
assistiot/open_api_frontend:1.0.1f11d82defc70
@babel/core@7.20.12
7.29.6

Open the chart page →

18,277
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
@babel/core@7.23.9
7.29.6

Open the chart page →

32,501
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
@babel/core@7.20.2
7.29.6

Open the chart page →

4,455
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
@babel/core@7.26.10
7.29.6
sysnet4admin/colosseum-prm:log5802bfcd7fed
@babel/core@7.26.10
7.29.6

Open the chart page →

26,996
overseerrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

overseerr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
linuxserver/overseerr:1.35.06108ed066d4a
@babel/core@7.20.7
7.29.6

Open the chart page →

3,071
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
@babel/core@7.28.5
7.29.6

Open the chart page →

7,405
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
@babel/core@7.1.0
7.29.6

Open the chart page →

25,456
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad3 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

3 of the 6 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
@babel/core@7.26.0
7.29.6
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
@babel/core@7.27.4
7.29.6
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
@babel/core@7.27.4
7.29.6

Open the chart page →

18,293
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
@babel/core@7.20.12
7.29.6

Open the chart page →

13,220
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
@babel/core@7.23.3
7.29.6

Open the chart page →

5,141
docker-composecoderstudio-strapi-devVerified publisher0.0.11 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
@babel/core@7.23.3
7.29.6

Open the chart page →

5,141
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
@babel/core@7.23.3
7.29.6

Open the chart page →

5,141
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
@babel/core@7.12.3
7.29.6

Open the chart page →

12,907
containers-security-chartscontainers-security0.1.01 of 7See more

containers-security-charts containers-security 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
coldatom/containers-security-front:latest7c2fbbb41bcf
@babel/core@7.20.12
7.29.6

Open the chart page →

9,146
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
cryptexlabs/authf:0.12.11189c07411d7c
@babel/core@7.25.2
7.29.6

Open the chart page →

3,769
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
@babel/core@7.26.8
7.29.6

Open the chart page →

2,529
dumpstoredumpstore0.1.11 of 2See more

dumpstore dumpstore 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
@babel/core@7.25.2
7.29.6

Open the chart page →

4,251
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
@babel/core@7.7.7
7.29.6

Open the chart page →

11,174
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
@babel/core@7.12.3
7.29.6

Open the chart page →

3,744
onboarding-faucetethersphereVerified publisher0.2.01 of 1See more

onboarding-faucet ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ethersphere/onboarding-faucet:0.3.0513154aab230
@babel/core@7.17.5
7.29.6

Open the chart page →

3,320
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
@babel/core@7.9.0
7.29.6

Open the chart page →

5,941
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
@babel/core@7.11.4
7.29.6

Open the chart page →

4,043
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
@babel/core@7.15.8
7.29.6

Open the chart page →

22,512
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
@babel/core@7.15.8
7.29.6

Open the chart page →

24,319
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
@babel/core@7.19.3
7.29.6

Open the chart page →

2,682
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
@babel/core@7.19.3
7.29.6

Open the chart page →

2,682
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
@babel/core@7.25.2
7.29.6

Open the chart page →

2,950
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
@babel/core@7.26.10
7.29.6

Open the chart page →

5,769
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
@babel/core@7.24.7
7.29.6

Open the chart page →

18,813
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
@babel/core@7.28.4
7.29.6

Open the chart page →

2,538
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
@babel/core@7.28.5
7.29.6

Open the chart page →

6,012
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
@babel/core@7.18.2
7.29.6

Open the chart page →

25,017
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
@babel/core@7.15.8
7.29.6

Open the chart page →

4,253
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
@babel/core@7.25.2
7.29.6

Open the chart page →

11,812
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
@babel/core@7.15.0
7.29.6

Open the chart page →

4,944
keyoxide-webittrident-oss0.2.31 of 1See more

keyoxide-web ittrident-oss 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
keyoxide/keyoxide:stable96f27a71269d
@babel/core@7.17.7
7.29.6

Open the chart page →

2,363
annotation-tooljtektVerified publisher0.1.51 of 2See more

annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
moreillon/api-proxy:a3e8b41e9e578c9653b6
@babel/core@7.18.2
7.29.6

Open the chart page →

2,315
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
@babel/core@7.23.3
7.29.6

Open the chart page →

22,589
polygonal-annotation-tooljtektVerified publisher0.1.51 of 2See more

polygonal-annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
moreillon/api-proxy:a3e8b41e9e578c9653b6
@babel/core@7.18.2
7.29.6

Open the chart page →

2,231
shinsei-managerjtektVerified publisher0.2.04 of 8See more

shinsei-manager jtekt 0.2.0

4 of the 8 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
@babel/core@7.21.0
7.29.6
moreillon/group-manager:latest3caa8f710ee0
@babel/core@7.25.2
7.29.6
moreillon/user-manager:v5.0.2e1c9bfab5c16
@babel/core@7.20.12
7.29.6
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
@babel/core@7.23.3
7.29.6

Open the chart page →

63,461
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
@babel/core@7.23.3
7.29.6

Open the chart page →

16,600
todo-appjunktext-via-aws1.2.101 of 1See more

todo-app junktext-via-aws 1.2.10

1 of the 1 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.34d44adf5a4da2
@babel/core@7.15.8
7.29.6

Open the chart page →

1,579
keycloak-multi-client-notifierkeycloak-multi-client-notifier2.1.21 of 2See more

keycloak-multi-client-notifier keycloak-multi-client-notifier 2.1.2

1 of the 2 container images this version deploys carry CVE-2026-49356.

Container imageDigestPackageFixed in
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
@babel/core@7.29.0
7.29.6

Open the chart page →

1,473

Container images carrying it

184 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
@babel/core@7.27.4
7.29.6
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
@babel/core@7.27.4
7.29.6
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
@babel/core@7.28.5
7.29.6
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
@babel/core@7.25.2
7.29.6
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
@babel/core@7.13.14
7.29.6
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
@babel/core@7.23.9
7.29.6
1
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
@babel/core@7.25.2
7.29.6
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
@babel/core@7.14.6
7.29.6
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
@babel/core@7.20.12
7.29.6
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
@babel/core@7.28.4
7.29.6
1
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
@babel/core@7.20.12
7.29.6
1
ghcr.io/rodg/nodecg-base:latest31be4bf87070
@babel/core@7.24.4
7.29.6
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
@babel/core@7.12.9
7.29.6
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
@babel/core@7.20.7
7.29.6
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
@babel/core@7.25.2
7.29.6
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
@babel/core@7.28.6
7.29.6
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
@babel/core@7.26.0
7.29.6
1
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
@babel/core@7.29.0
7.29.6
1
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
@babel/core@7.27.4
7.29.6
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
@babel/core@7.23.6
7.29.6
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
@babel/core@7.24.5
7.29.6
1
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
@babel/core@7.29.0
7.29.6
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
@babel/core@7.27.7
7.29.6
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
@babel/core@7.23.3
7.29.6
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
@babel/core@7.23.3
7.29.6
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
@babel/core@7.23.3
7.29.6
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
@babel/core@7.15.5
7.29.6
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
@babel/core@7.1.0
7.29.6
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
@babel/core@7.12.3
7.29.6
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
@babel/core@7.15.5
7.29.6
1
quay.io/wekan/wekan:v5.65cb17600883a3
@babel/core@7.15.8
7.29.6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
@babel/core@7.29.0
7.29.6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
@babel/core@7.27.4
7.29.6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
@babel/core@7.29.0
7.29.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.