Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29745 | esm.sh has File Inclusion issue |
Github GHSA |
GHSA-49pv-gwxp-532r | esm.sh has File Inclusion issue |
Thu, 18 Sep 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Esm-dev
Esm-dev esmsh |
|
| Vendors & Products |
Esm-dev
Esm-dev esmsh |
Wed, 17 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 17 Sep 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a Local File Inclusion (LFI) issue was identified in the esm.sh service URL handling. An attacker could craft a request that causes the server to read and return files from the host filesystem (or other unintended file sources). | |
| Title | Local File Inclusion in esm.sh | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-17T18:09:50.796Z
Reserved: 2025-09-12T12:36:24.635Z
Link: CVE-2025-59341
Updated: 2025-09-17T18:08:00.532Z
Status : Deferred
Published: 2025-09-17T18:15:53.393
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-59341
No data.
OpenCVE Enrichment
Updated: 2025-09-18T12:41:13Z
EUVD
Github GHSA