esm
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 7 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from November 29, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →esm.sh has SSRF localhost/private-network bypass in `/http(s)` module route
esm.sh is vulnerable to full-response SSRF
esm.sh has path traversal in `extractPackageTarball` that enables file writes from malicious packages
esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript
esm.sh CDN service has arbitrary file write via tarslip
Monitor esm in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.