CVE-2025-59341 HIGH

CVE-2025-59341: Local File Inclusion in esm.sh

Vendor Esm-Dev
Product esm.sh
Weakness CWE-23
Published September 17, 2025
Last update September 17, 2025

CVSS base score

7.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a Local File Inclusion (LFI) issue was identified in the esm.sh service URL handling. An attacker could craft a request that causes the server to read and return files from the host filesystem (or other unintended file sources).

Key dates

02Disclosure timeline

September 17, 2025 CVE published
September 17, 2025 Record updated