CVE-2025-50180
EUVD-2025-20811425.02.2026, 16:23
esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-response SSRF, allowing an attacker to retrieve information from internal websites through the vulnerability. Version 137 fixes the vulnerability.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| esm | esm.sh | 𝑥 < 137 |
𝑥
= Vulnerable software versions
References