CVE-2025-59342Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw in the handling of the X-Zone-Id HTTP header allows an attacker to cause the application to write files outside the intended storage location. The header value is used to build a filesystem path but is not properly canonicalized or restricted to the application’s storage base directory. As a result, supplying ../ sequences in X-Zone-Id causes files to be written to arbitrary directories. Version 136.1 contains a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-24

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-17); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-17: 1Mentions · 2026-05-12: 1Technical Details · 2026-04-17: 1Technical Details · 2026-05-12: 104-1705-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-59342 - medium 🚨 http://esm.sh <= v136 - Arbitrary File Write via Path Traversal > http://esm.sh <= 136 contains a path traversal caused by improper canonicalization of the X-... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-59342 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE‑2025‑59342, describing an arbitrary file write via path traversal in esm.sh versions up to 136, and provides links for further details.

    00001540
    930 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 esmsh, Path Traversal, #CVE-2025-59342 (Medium) https://dailycve.com/esmsh-path-traversal-cve-2025-59342-medium/

    Post summary

    A medium‑severity path traversal vulnerability (CVE‑2025‑59342) has been disclosed, but the text only provides the CVE reference without PoC, exploit code, or mitigation details.

    00000803
    203 followersView on X

Explore more