Search/CVE-2025-59342
CVE

CVE-2025-59342

esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw in the handling of the X-Zone-Id HTTP header allows an attacker to cause the application to write files outside the intended storage location. The header value is used to build a filesystem path but is not properly canonicalized or restricted to the application’s storage base directory. As a result, supplying ../ sequences in X-Zone-Id causes files to be written to arbitrary directories. Version 136.1 contains a patch.

CVSS v3.1
EPSS
3.03%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Aug 19, 2026
0.20pp
2.83% → 3.03% over 2 tracked changes
Connections
1 relationships
Timeline
disclosure → media coverage
Sep 17, 2025
Disclosure — published as a CVE record. · last revised by NVD Apr 15, 2026
Public PoC (1)
Unverified third-party code — review before executing.