Vulnerability library
Security checkJune 12, 2026

esbuild allows arbitrary file read when running the development server on Windows

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Low severitynpmesbuild

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

The development server contains a path traversal vulnerability on Windows when serving files from servedir.

Due to the use of path.Clean() (which only normalizes forward-slash / separators) instead of a Windows-aware path normalization function, it is possible to craft requests using backslashes (\) that bypass the intended directory containment logic.

Recommendation

Update the esbuild package to the latest compatible version. Followings are version details:

  • Affected version(s): >= 0.27.3, < 0.28.1
  • Patched version(s): 0.28.1

References

Could your website be exposed too?

SmartScanner can check your website for esbuild allows arbitrary file read when running the development server on Windows and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated June 12, 2026