HIGH
esm.sh: Legacy Route Path Traversal Can Lead to RCE
Published May 28, 2026
8.7
HIGHCVSS 4.0
EPSS 0.50%
Description
esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first retrieves a response from legacyServer, parses the incoming request path, and ultimately writes the data to storage via buildStorage.Put. The router concatenates the path components without sanitizing them, producing a storage key. When this key is used, the underlying file system resolves the relative segments and writes the file to the specified path. Thus an attacker can craft a request that writes data to arbitrary locations on the server.
Affected products
-
- Version <= 137StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/esm-dev/esm.sh
Go
Introduced 0 Fixed 0.0.0-20260508100112-1960055e1d53
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/esm-dev/esm.sh | 0 | 0.0.0-20260508100112-1960055e1d53 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-32910 Advisory
- https://github.com/advisories/GHSA-3636-h3vx-6465 Advisory
- https://github.com/esm-dev/esm.sh/releases/tag/v137_3
- https://github.com/esm-dev/esm.sh/security/advisories/GHSA-3636-h3vx-6465 exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-44593
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 28, 2026
Updated Jun 2, 2026
Reserved May 6, 2026
Link CVE-2026-44593
CISA Vulnrichment
Updated Jun 2, 2026
ENISA EUVD
EUVD-2026-32910 GHSA-3636-H3VX-6465 Assigner GitHub_M
Published May 28, 2026
Updated Jun 2, 2026
Exploited since n/a
Link EUVD-2026-32910