MEDIUM

CVE-2025-59689

Libraesva Email Security Gateway 2025-09-19 CVSS v3.1
CVSS
6.1
KEV

Description

Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.

Summary dbcve.org

Libraesva Email Security Gateway versions 4.5 through 5.5.x before 5.5.7 contains a command injection vulnerability in the compressed email attachment processing function. An attacker can execute arbitrary OS commands by embedding malicious payloads within compressed attachments (such as zip, tar, or gz files) that the gateway unpacks and processes without proper input sanitization.

Mitigation

Upgrade Libraesva ESG to version 5.0.31, 5.1.20, 5.2.31, 5.4.8, or 5.5.7 (or later) to patch the command injection vulnerability. As a temporary mitigation, consider filtering or quarantining compressed attachments at the MTA layer until the upgrade can be completed.

Weakness (CWE)

CWE-77 Command Injection

EPSS Score

1.86%
Probability of exploitation in next 30 days
78.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE