
CVE-2025-50180 http://esm.sh is a no-build content delivery network (CDN) for web development. In version 136, http://esm.sh is vulnerable to a full-response SSRF, allowing an attacker to retriev… https://www.cve.org/CVERecord?id=CVE-2025-50180
Post summary
The post reports that CVE‑2025‑50180 affects esm.sh v136, enabling a full‑response SSRF, but provides no PoC, exploit, patch, or evidence of active exploitation.
