esbuild vulnerabilities
CVEs whose affected-version data names the esbuild package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
GHSA-g7r4-m6w7-qqqrLow· 2.5esbuild allows arbitrary file read when running the development server on Windows
esbuild allows arbitrary file read when running the development server on Windows
▾ Sunlitesbuild · esbuildvia GHSA
GHSA-gv7w-rqvm-qjhrHigh· 8.1Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY
Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY
▾ Twilightesbuild · esbuildvia GHSA