Esm.sh
Esm · 5 CVEs
CVE-2026-27730
HIGH
esm.sh has SSRF localhost/private-network bypass in `/http(s)` module route
Feb 25, 2026
CVE-2025-50180
HIGH
esm.sh is vulnerable to full-response SSRF
Feb 25, 2026
CVE-2026-23644
HIGH
esm.sh has path traversal in `extractPackageTarball` that enables file writes from malicious packages
Jan 18, 2026
CVE-2025-65026
CRITICAL
esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript
Nov 19, 2025
CVE-2025-65025
CRITICAL
esm.sh CDN service has arbitrary file write via tarslip
Nov 19, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-27730 | esm.sh has SSRF localhost/private-network bypass in `/http(s)` module route | HIGH | 0.47% | Feb 25, 2026 |
| CVE-2025-50180 | esm.sh is vulnerable to full-response SSRF | HIGH | 0.39% | Feb 25, 2026 |
| CVE-2026-23644 | esm.sh has path traversal in `extractPackageTarball` that enables file writes from malicious packages | HIGH | 0.55% | Jan 18, 2026 |
| CVE-2025-65026 | esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript | CRITICAL | 0.48% | Nov 19, 2025 |
| CVE-2025-65025 | esm.sh CDN service has arbitrary file write via tarslip | CRITICAL | 0.53% | Nov 19, 2025 |
Showing 1 to 5 of 5 CVEs