—
GO-2025-3967
esm.sh has arbitrary file write via path traversal in `X-Zone-Id` header in github.com/esm-dev/esm.sh
Details
esm.sh has arbitrary file write via path traversal in `X-Zone-Id` header in github.com/esm-dev/esm.sh
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/esm-dev/esm.sh
Introduced in:
0No fixed version published yet for github.com/esm-dev/esm.sh (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/esm-dev/esm.sh/security/advisories/GHSA-g2h5-cvvr-7gmw[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2025-59342[ADVISORY]
- https://github.com/esm-dev/esm.sh/commit/833a29f42aeb0acbd7089a71be11dd0a292d3151[FIX]
- https://github.com/esm-dev/esm.sh/blob/main/server/router.go#L116[WEB]
- https://github.com/esm-dev/esm.sh/blob/main/server/router.go#L411[WEB]