npm package report

Is esm safe?

1 known vulnerability, worst severity MODERATE.

// reach

23 direct dependencies

9 carry known advisories, worst CRITICAL

33 packages depend on it

an advisory here reaches each of them

Create a free accountfor every dependency path, dependent and what to upgrade
// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


cvss
0.0
medium

severity band, no base score published

epss
not scored

chance of exploitation in 30 days

xyz score
not scored

CyberXYZ composite out of 10

fig. 01 — GHSA-qx4v-6gc5-f2vv, the advisory selected below

// 1 advisories

GHSA-qx4v-6gc5-f2vv

MODERATE

A Regular Expression Denial of Service vulnerability was discovered in esm before 3.1.0. The issue is that esm's find-indexes is using the unescaped identifiers in a regex, which, in this case, causes an infinite loop.


Checked 2026-10-03 at 18:56 UTC. The most recent advisory here was published 2019-06-20. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.