<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 11:09:50 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322483</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322483</link>
      <description>EUVD-2026-322483</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322483</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44594</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44594</link>
      <description>&lt;p&gt;esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild plugin&amp;#39;s handling of the browser field in package.json. An attacker can publish an npm package that causes the server to read and return arbitrary files from the host filesystem during the build process.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild plugin&amp;#39;s handling of the browser field in package.json. An attacker can publish an npm package that causes the server to read and return arbitrary files from the host filesystem during the build process.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44594</guid>
    </item>
    <item>
      <title>GHSA-rg65-45m7-hq57 — esm.sh: Path Traversal via package.json browser field allows reading arbitrary server files</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rg65-45m7-hq57</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/esm-dev/esm.sh&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A Local File Inclusion (LFI) vulnerability exists in the esbuild plugin&amp;#39;s handling of the `browser` field in `package.json`. An attacker can publish an npm package that causes the server to read and return arbitrary files from the host filesystem during the build process.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable code is in the `OnResolve` callback of the esbuild plugin:&lt;/p&gt;
&lt;p&gt;https://github.com/esm-dev/esm.sh/blob/main/server/build.go&lt;/p&gt;
&lt;p&gt;The plugin validates that resolved file paths stay within the package working directory. However, after this check, the `browser` field from `package.json` remaps the module path to an attacker-controlled value containing `../` sequences. No validation is performed after the remapping.&lt;/p&gt;
&lt;p&gt;```go
// Sandbox check passes for the original &amp;#34;./d1.txt&amp;#34; path
if !strings.HasPrefix(filename, ctx.wd+string(os.PathSeparator)) {
    return esbuild.OnResolveResult{}, fmt.Errorf(&amp;#34;could not resolve module %s&amp;#34;, specifier)
}&lt;/p&gt;
&lt;p&gt;// ... later, browser field remaps to attacker-controlled path:
if len(pkgJson.Browser) &amp;gt; 0 &amp;amp;&amp;amp; ctx.isBrowserTarget() {
	if path, ok := pkgJson.Browser[modulePath]; ok {
		if path == &amp;#34;&amp;#34; {
			return esbuild.OnResolveResult{
				Path:      args.Path,
				Namespace: &amp;#34;browser-exclude&amp;#34;,
			}, nil
		}
		if !isRelPathSpecifier(path) {
			externalPath, sideEffects, err := ctx.resolveExternalModule(path, args.Kind, withTypeJSON, analyzeMode)
			if err != nil {
				return esbuild.OnResolveResult{}, err
			}
			return esbuild.OnResolveResult{
				Path:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/esm-dev/esm.sh&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A Local File Inclusion (LFI) vulnerability exists in the esbuild plugin&amp;#39;s handling of the `browser` field in `package.json`. An attacker can publish an npm package that causes the server to read and return arbitrary files from the host filesystem during the build process.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable code is in the `OnResolve` callback of the esbuild plugin:&lt;/p&gt;
&lt;p&gt;https://github.com/esm-dev/esm.sh/blob/main/server/build.go&lt;/p&gt;
&lt;p&gt;The plugin validates that resolved file paths stay within the package working directory. However, after this check, the `browser` field from `package.json` remaps the module path to an attacker-controlled value containing `../` sequences. No validation is performed after the remapping.&lt;/p&gt;
&lt;p&gt;```go
// Sandbox check passes for the original &amp;#34;./d1.txt&amp;#34; path
if !strings.HasPrefix(filename, ctx.wd+string(os.PathSeparator)) {
    return esbuild.OnResolveResult{}, fmt.Errorf(&amp;#34;could not resolve module %s&amp;#34;, specifier)
}&lt;/p&gt;
&lt;p&gt;// ... later, browser field remaps to attacker-controlled path:
if len(pkgJson.Browser) &amp;gt; 0 &amp;amp;&amp;amp; ctx.isBrowserTarget() {
	if path, ok := pkgJson.Browser[modulePath]; ok {
		if path == &amp;#34;&amp;#34; {
			return esbuild.OnResolveResult{
				Path:      args.Path,
				Namespace: &amp;#34;browser-exclude&amp;#34;,
			}, nil
		}
		if !isRelPathSpecifier(path) {
			externalPath, sideEffects, err := ctx.resolveExternalModule(path, args.Kind, withTypeJSON, analyzeMode)
			if err != nil {
				return esbuild.OnResolveResult{}, err
			}
			return esbuild.OnResolveResult{
				Path:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rg65-45m7-hq57</guid>
    </item>
  </channel>
</rss>
