S4E just found a high-severity finding from snmp credential disclosure scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2025-59342

5.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.
Description

esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw in the handling of the X-Zone-Id HTTP header allows an attacker to cause the application to write files outside the intended storage location. The header value is used to build a filesystem path but is not properly canonicalized or restricted to the application’s storage base directory. As a result, supplying ../ sequences in X-Zone-Id causes files to be written to arbitrary directories. Version 136.1 contains a patch.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
esm.sh
Updated Sep 18, 2026View on NVD →
S4E scanner

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →