CVE-2026-44594

esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the browser field in package.json. An attacker can publish an npm package that causes the server to read and return arbitrary files from the host filesystem during the build process.
Configurations

No configuration.

History

28 May 2026, 17:16

Type Values Removed Values Added
References () https://github.com/esm-dev/esm.sh/security/advisories/GHSA-rg65-45m7-hq57 - () https://github.com/esm-dev/esm.sh/security/advisories/GHSA-rg65-45m7-hq57 -

28 May 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 16:16

Updated : 2026-05-29 16:32


NVD link : CVE-2026-44594

Mitre link : CVE-2026-44594

CVE.ORG link : CVE-2026-44594


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')