Back to Database
Status published
High
CVE-2025-50180
esm.sh is vulnerable to full-response SSRF
Vulnerability Description
esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-response SSRF, allowing an attacker to retrieve information from internal websites through the vulnerability. Version 137 fixes the vulnerability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-50180
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/esm-dev/esm.sh/security/advisories/GHSA-3c9r-837r-qqm4
- https://github.com/esm-dev/esm.sh/pull/1149
- https://github.com/esm-dev/esm.sh/commit/0593516c4cfab49ad3b4900416a8432ff2e23eb0
- https://github.com/esm-dev/esm.sh/blob/f80ff8c8d58749e77fa964abde468fc61f8bd89e/internal/fetch/fetch.go#L13
- https://github.com/esm-dev/esm.sh/blob/f80ff8c8d58749e77fa964abde468fc61f8bd89e/server/router.go#L511
- https://github.com/esm-dev/esm.sh/releases/tag/v137
More from esm-dev
View All →CVE-2025-65026
esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript
Medium
6.1
CVE-2025-65025
esm.sh CDN service has arbitrary file write via tarslip
High
8.2
CVE-2025-59342
esm.sh writes arbitrary files via path traversal in `X-Zone-Id` header
Medium
5.5
CVE-2025-59341
Local File Inclusion in esm.sh
High
7.7
Affected Vendor
esm-dev
View all reports →Affected Software
esm.sh
Vulnerable Versions:
= 136
Timeline
Official Publish:
February 25th, 2026
Last Modified:
February 27th, 2026
Added to House:
July 22nd, 2026