Executive brief
A vulnerability in the esm.sh content delivery network allows attackers to read sensitive files from the server's host filesystem. By publishing a malicious package to npm and requesting it through the service, an attacker could steal configuration files, authentication tokens, and cloud storage credentials. This could lead to a full compromise of the service's infrastructure and customer data.
Technical details
A Local File Inclusion (LFI) / Path Traversal vulnerability exists in the esbuild plugin within esm.sh's server/build.go. While the plugin initially validates that resolved paths are within the package's working directory, it fails to re-validate paths after they are remapped via the 'browser' field in package.json. An attacker can use '../' sequences in this field to escape the sandbox. The contents of the resulting files are then leaked through the bundled JavaScript output or the 'sourcesContent' array in source maps. This can be used to read sensitive files like config.json, which may contain npm registry tokens or S3 credentials. The vulnerability is patched in version 0.0.0-20250616164159-0593516c4cfa.
Affected products
- esm-dev esm.sh < 0.0.0-20250616164159-0593516c4cfa
Timeline
- 2026-05-08: disclosed
- 2026-05-12: advisory
- 2026-05-28: other: NVD published
References
- https://api.github.com/users/donttrytofindme
- https://github.com/donttrytofindme
- https://api.github.com/users/donttrytofindme/gists%7B/gist_id%7D
- https://api.github.com/users/donttrytofindme/repos
- https://avatars.githubusercontent.com/u/274643975?v=4
- https://api.github.com/users/donttrytofindme/events%7B/privacy%7D