Security Advisory

CVE-2025-65025

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-11-19 17:32:46
Last updated 2025-11-20 14:09:44
Assigner GitHub_M
State PUBLISHED

Description

esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, the esm.sh CDN service is vulnerable to path traversal during NPM package tarball extraction. An attacker can craft a malicious NPM package containing specially crafted file paths (e.g., package/../../tmp/evil.js). When esm.sh downloads and extracts this package, files may be written to arbitrary locations on the server, escaping the intended extraction directory. This issue has been patched in version 136.