Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2657-3c98-63jq | esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages |
Wed, 18 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Esm
Esm esm.sh |
|
| CPEs | cpe:2.3:a:esm:esm.sh:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Esm
Esm esm.sh |
|
| Metrics |
cvssV3_1
|
Tue, 20 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 19 Jan 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Esm-dev
Esm-dev esmsh |
|
| Vendors & Products |
Esm-dev
Esm-dev esmsh |
Sun, 18 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | esm.sh is a no-build content delivery network (CDN) for web development. Prior to Go pseeudoversion 0.0.0-20260116051925-c62ab83c589e, the software has a path traversal vulnerability due to an incomplete fix. `path.Clean` normalizes a path but does not prevent absolute paths in a malicious tar file. Commit https://github.com/esm-dev/esm.sh/commit/9d77b88c320733ff6689d938d85d246a3af9af16, corresponding to pseudoversion 0.0.0-20260116051925-c62ab83c589e, fixes this issue. | |
| Title | esm.sh has path traversal in `extractPackageTarball` that enables file writes from malicious packages | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-20T20:06:58.947Z
Reserved: 2026-01-14T16:08:37.484Z
Link: CVE-2026-23644
Updated: 2026-01-20T20:04:09.482Z
Status : Analyzed
Published: 2026-01-18T23:15:48.547
Modified: 2026-02-18T16:10:48.287
Link: CVE-2026-23644
No data.
OpenCVE Enrichment
Updated: 2026-04-18T05:30:25Z
Github GHSA