« Volver al listado

ESM

Esm.sh: vulnerabilidades y CVE

Esm.sh tiene 9 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses7
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-44594Alta (7.5)0.48%—28 may 2026
esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the browser field in package.json. An…
CVE-2026-44593Alta (8.7)0.50%—28 may 2026
esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first retrieves a response from legacyServer, parses the incoming request path, and ultimately writes the…
CVE-2026-27730Alta (7.5)0.47%—25 feb 2026
esm.sh is a no-build content delivery network (CDN) for web development. Versions up to and including 137 have an SSRF vulnerability (CWE-918) in esm.sh’s `/http(s)` fetch route. The service tries to block…
CVE-2025-50180Alta (8.7)0.39%—25 feb 2026
esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-response SSRF, allowing an attacker to retrieve information from internal websites through the…
CVE-2026-23644Alta (7.7)0.55%—18 ene 2026
esm.sh is a no-build content delivery network (CDN) for web development. Prior to Go pseeudoversion 0.0.0-20260116051925-c62ab83c589e, the software has a path traversal vulnerability due to an incomplete fix.…
CVE-2025-65026Crítica (9.6)0.48%—19 nov 2025
esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, The esm.sh CDN service contains a Template Literal Injection vulnerability (CWE-94) in its CSS-to-JavaScript module…
CVE-2025-65025Crítica (9.8)0.53%—19 nov 2025
esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, the esm.sh CDN service is vulnerable to path traversal during NPM package tarball extraction. An attacker can craft a…
CVE-2025-59342Media (5.5)3.0%—17 sept 2025
esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw in the handling of the X-Zone-Id HTTP header allows an attacker to cause the application to write…
CVE-2025-59341Alta (7.7)1.6%—17 sept 2025
esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a Local File Inclusion (LFI) issue was identified in the esm.sh service URL handling. An attacker could craft a request…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application7
  2. T1005 Data from Local System4
  3. T1090 Proxy2
  4. T1059.007 JavaScript1
  5. T1189 Drive-by Compromise1
  6. T1565.002 Transmitted Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.