CVE 7.5 HIGH

esm.sh: Path Traversal via package.json browser field allows reading arbitrary server files_CVE-2026-44594

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the browser field in package.json. An attacker can publish an npm package that causes the server to read and return arbitrary files from the host filesystem during the build process.

Basic Information

ID CVE-2026-44594
Source GitHub_M
Published May 28, 2026 at 14:45
Modified May 28, 2026 at 15:31

Affected Product

Vendor esm-dev
Product esm.sh
Version <= 137
Affected Versions esm-dev esm.sh <= 137

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.