A vulnerability, which was classified as critical, has been found in esm-dev esm.sh up to 137. This vulnerability affects unknown code. This manipulation causes path traversal.

This vulnerability is tracked as CVE-2026-44594. The attack is possible to be carried out remotely. No exploit exists.