References https://nvd.nist.gov/vuln/detail/CVE-2025-59341 https://github.com/advisories/GHSA-49pv-gwxp-532r https://github.com/esm-dev/esm.sh/security/advisories/GHSA-49pv-gwxp-532r https://access.redhat.com/security/cve/cve-2025-59341 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-59341.yaml https://vulners.com/cve/CVE-2025-59341 https://s4e.io/tools/esmsh-local-file-inclusion-cve-2025-59341 https://guide.sonatype.com/vulnerability/CVE-2025-59341
Related VulnerabilitiesPoCCVE-2025-59341: esm.sh <= v136 - Local File InclusionPoCCVE-2025-59342: esm.sh <= v136 - Arbitrary File Write via Path Traversalesm.sh /pr/x/y@99 目录遍历漏洞(CVE-2025-59341)PoCesmtprc-config: eSMTP - Config Discovery用友U8+crm bgt/recievesms.php存在sql注入漏洞