{"id":"CVE-2025-65025","aliases":["GHSA-h3mw-4f23-gwpw","GO-2025-4138"],"url":"https://o3.security/vulnerability/CVE-2025-65025","summary":"esm.sh CDN service has arbitrary file write via tarslip","details":"esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, the esm.sh CDN service is vulnerable to path traversal during NPM package tarball extraction. An attacker can craft a malicious NPM package containing specially crafted file paths (e.g., package/../../tmp/evil.js). When esm.sh downloads and extracts this package, files may be written to arbitrary locations on the server, escaping the intended extraction directory. This issue has been patched in version 136.","published":"2025-11-19T17:32:46.835Z","modified":"2026-08-08T03:48:15.765813233Z","cvss":{"score":8.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/esm-dev/esm.sh","fixedVersion":"0.0.0-20251117232647-9d77b88c3207"}],"fix":{"url":"https://github.com/esm-dev/esm.sh/commit/9d77b88c320733ff6689d938d85d246a3af9af16","label":"esm-dev/esm.sh@9d77b88"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/65xxx/CVE-2025-65025.json"},{"type":"ADVISORY","url":"https://github.com/esm-dev/esm.sh/security/advisories/GHSA-h3mw-4f23-gwpw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-65025"},{"type":"FIX","url":"https://github.com/esm-dev/esm.sh/commit/9d77b88c320733ff6689d938d85d246a3af9af16"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:15.765813233Z"}}