/Vulnerability Library

esm.sh <= v136 - Arbitrary File Write via Path Traversal

CVE-2025-59342
Verified

Description

esm.sh <= 136 contains a path traversal caused by improper canonicalization of the X-Zone-Id HTTP header, letting attackers write files outside the intended storage directory, exploit requires crafted header input.

Severity

Medium

CVSS Score

5.3

Exploit Probability

3%

Affected Product

esm.sh

Published Date

April 17, 2026

Template Author

0x_akoko

CVE-2025-59342.yaml
5.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVE ID:
cve-2025-59342
CWE ID:
cwe-24

References

https://github.com/esm-dev/esm.sh/security/advisories/GHSA-g2h5-cvvr-7gmwhttps://www.exploit-db.com/exploits/52461https://nvd.nist.gov/vuln/detail/CVE-2025-59342

Remediation Steps

Update to a version later than 136 or the latest available version.