Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-59342

41
FAUCET Score

CVE-2025-59342 describes a path traversal vulnerability in esm.sh versions 136 and earlier, a nobuild content delivery network. An attacker can manipulate the X-Zone-Id HTTP header to write files to arbitrary directories outside the intended storage location. With a CVSS score of 5.5 (Medium), this vulnerability has a network attack vector, low attack complexity, and can lead to unauthorized file creation or modification. While not currently in the KEV catalog or actively exploited, public exploit code (EDB-52461) is available, though community discussion and media coverage are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
Esm-DevEsm.Sh
<= 136CNA affected

CVSS Data

CVSS version used by this source: 4.0

5.5MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
2.83%
Probability of exploitation in next 30 days
EPSS Percentile
85.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Nuclei: CVE-2025-59342 · Apr 17, 2026
ExploitDB: EDB-52461 · Dec 16, 2025
This CVE's current EPSS score of 0.0283 is in the 79th percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/esm-dev/esm.shFixed in: 136.1

Vendor Advisories (1)

goGHSA-g2h5-cvvr-7gmwmedium

esm.sh has arbitrary file write via path traversal in `X-Zone-Id` header

Sep 17, 2025

References

github.com / esm-dev/esm.sh/blob/main/server/router.go
github.com / esm-dev/esm.sh/blob/main/server/router.go
github.com / esm-dev/esm.sh/commit/833a29f42aeb0acbd7089a71be11dd0a292d3151
github.com / esm-dev/esm.sh/security/advisories/GHSA-g2h5-cvvr-7gmw