VendorsEsmesm.shall versions
Vulnerabilities

Esm .sh (Server)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2025-65025
esm.sh CDN service has arbitrary file write via tarslip
Published 2025-11-19 · Analyzed
9.8EPSS 0.005
CVE-2025-65026
esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript
Published 2025-11-19 · Analyzed
9.6EPSS 0.005
CVE-2025-50180
esm.sh is vulnerable to full-response SSRF
Published 2026-02-25 · Analyzed
8.7EPSS 0.004
CVE-2026-27730
esm.sh has SSRF localhost/private-network bypass in `/http(s)` module route
Published 2026-02-25 · Analyzed
8.6EPSS 0.005
CVE-2026-23644
esm.sh has path traversal in `extractPackageTarball` that enables file writes from malicious packages
Published 2026-01-18 · Analyzed
7.7EPSS 0.005