esm.sh是esm.sh开源的一个内容分发网络。 esm.sh 136及之前版本存在安全漏洞,该漏洞源于X-Zone-Id HTTP标头处理不当,可能导致路径遍历攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Exploit Path Traversal in esm-dev | https://github.com/byteReaper77/CVE-2025-59342 | POC Details |
| 2 | esm.sh <= 136 contains a path traversal caused by improper canonicalization of the X-Zone-Id HTTP header, letting attackers write files outside the intended storage directory, exploit requires crafted header input. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-59342.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet