Executive brief
esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages
Affected products
- Go github.com/esm-dev/esm.sh
Junglewise Threat Intelligence
CVE-2026-23644 · Severity: medium · CVSS 4 · Published 2026-02-26
Technologies: github.com/esm-dev/esm.sh (Go). Vendors: Go.
esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages