esm.sh <= 136 contains a path traversal caused by improper canonicalization of the X-Zone-Id HTTP header, letting attackers write files outside the intended storage directory, exploit requires crafted header input.
id: CVE-2025-59342
info:
name: esm.sh <= v136 - Arbitrary File Write via Path Traversal
author:
...