CVE-2025-59342 describes a path traversal vulnerability in esm.sh versions 136 and earlier, a nobuild content delivery network. An attacker can manipulate the X-Zone-Id HTTP header to write files to arbitrary directories outside the intended storage location. With a CVSS score of 5.5 (Medium), this vulnerability has a network attack vector, low attack complexity, and can lead to unauthorized file creation or modification. While not currently in the KEV catalog or actively exploited, public exploit code (EDB-52461) is available, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Esm-Dev | Esm.Sh | <= 136CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.