CVE-2025-65026 describes a Critical Template Literal Injection vulnerability (CWE-94) in the esm.sh CDN service, affecting versions prior to 136. An attacker can inject malicious JavaScript via specially crafted CSS files requested with the ?module parameter, leading to Cross-Site Scripting (XSS) in browsers and Remote Code Execution (RCE) in Electron applications. With a CVSS score of 9.6, this vulnerability is easily exploitable over the network with low attack complexity, requiring user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 136CPE matchmatch criteria | cpe:2.3:a:esm:esm.sh:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.