VDB
GO-2025-4139
GO-2025-4139
PUBLISHED
esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript in github.com/esm-dev/esm.sh
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | esm-dev/esm.sh | 0, 0 |
Timeline
- Nov 25, 2025 CVE Published
- Mar 3, 2026 CVE Updated
- May 1, 2026 Security Advisory