Vulnerability Description
esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the browser field in package.json. An attacker can publish an npm package that causes the server to read and return arbitrary files from the host filesystem during the build process.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/esm-dev/esm.sh/security/advisories/GHSA-rg65-45m7-hq57
- https://github.com/esm-dev/esm.sh/security/advisories/GHSA-rg65-45m7-hq57
FAQ
What is CVE-2026-44594?
CVE-2026-44594 is a vulnerability with a CVSS score of 7.5 (HIGH). esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the browser field in ...
How severe is CVE-2026-44594?
CVE-2026-44594 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44594?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.