Skip to content

Known CVE

esm.sh <= v136 - Arbitrary File Write via Path Traversal

esm.sh <= 136 contains a path traversal caused by improper canonicalization of the X-Zone-Id HTTP header, letting attackers write files outside the intended storage directory, exploit requires crafted header input.

CVE-2025-59342

Medium2025CVSS 5.3CWE-24

cve2025 · esm · path-traversal · file-write · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website