VDB
KO

package

npm / esbuild

pkg:npm/esbuild

MEDIUM 5.3 npm
GHSA-67mh-4wv8-2f99

esbuild enables any website to send any requests to the development server and read the response

Modified: 2/4/2026

LOW 2.5 npm
GHSA-g7r4-m6w7-qqqr

esbuild allows arbitrary file read when running the development server on Windows

Modified: 6/15/2026

HIGH 8.1 npm
GHSA-gv7w-rqvm-qjhr

esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY

Modified: 6/15/2026