esm.sh <= v136 - Arbitrary File Write via Path Traversal
CVE-2025-59342
Verified
Description
esm.sh <= 136 contains a path traversal caused by improper canonicalization of the X-Zone-Id HTTP header, letting attackers write files outside the intended storage directory, exploit requires crafted header input.
Severity
Medium
CVSS Score
5.3
Exploit Probability
3%
Affected Product
esm.sh
Published Date
April 17, 2026
Template Author
0x_akoko
CVE-2025-59342.yaml
5.3Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVE ID:
cve-2025-59342
CWE ID:
cwe-24
Remediation Steps
Update to a version later than 136 or the latest available version.