Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3636-h3vx-6465 | esm.sh: Legacy Route Path Traversal Can Lead to RCE |
Tue, 02 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 30 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Esm-dev
Esm-dev esmsh |
|
| Vendors & Products |
Esm-dev
Esm-dev esmsh |
Thu, 28 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first retrieves a response from legacyServer, parses the incoming request path, and ultimately writes the data to storage via buildStorage.Put. The router concatenates the path components without sanitizing them, producing a storage key. When this key is used, the underlying file system resolves the relative segments and writes the file to the specified path. Thus an attacker can craft a request that writes data to arbitrary locations on the server. | |
| Title | esm.sh: Legacy Route Path Traversal Can Lead to RCE | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-02T15:01:05.268Z
Reserved: 2026-05-06T21:49:12.425Z
Link: CVE-2026-44593
Updated: 2026-06-02T14:59:45.872Z
Status : Deferred
Published: 2026-05-28T16:16:24.587
Modified: 2026-06-02T16:16:41.203
Link: CVE-2026-44593
No data.
OpenCVE Enrichment
Updated: 2026-05-30T21:00:12Z
Github GHSA