CVE-2025-50180

esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-response SSRF, allowing an attacker to retrieve information from internal websites through the vulnerability. Version 137 fixes the vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:esm:esm.sh:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-25 16:23

Updated : 2026-02-27 17:44


NVD link : CVE-2025-50180

Mitre link : CVE-2025-50180

CVE.ORG link : CVE-2025-50180


JSON object : View

Products Affected

esm

  • esm.sh
CWE
CWE-918

Server-Side Request Forgery (SSRF)