Skip to content
Noroxi

esm records

5 published records for vendor esm.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

5 records
  • esm.sh CDN service has arbitrary file write via tarslip

    CriticalCVSS 9.8No exploitEPSS 1%

    esm · esm.shNov 19, 2025

  • esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript

    CriticalCVSS 9.6No exploitEPSS 0%

    esm · esm.shNov 19, 2025

  • esm.sh is vulnerable to full-response SSRF

    HighCVSS 8.7No exploitEPSS 0%

    esm · esm.shFeb 25, 2026

  • esm.sh has path traversal in `extractPackageTarball` that enables file writes from malicious packages

    HighCVSS 7.7No exploitEPSS 1%

    esm · esm.shJan 18, 2026

  • esm.sh has SSRF localhost/private-network bypass in `/http(s)` module route

    HighCVSS 7.5No exploitEPSS 0%

    esm · esm.shFeb 25, 2026