cbcvebase.
CVE-2025-59518
published 2025-09-17

CVE-2025-59518: In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule…

PriorityP353high8CVSS 3.1
AVNACHPRHUINSCCHIHAH
EPSS
1.19%
64.5th percentile
In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.

Affected

3 ranges
VendorProductVersion rangeFixed in
debianlemonldap-ng< lemonldap-ng 2.16.1+ds-deb12u7 (bookworm)lemonldap-ng 2.16.1+ds-deb12u7 (bookworm)
lemonldap-nglemonldap_ng< 2.16.72.16.7
lemonldap-nglemonldap_ng>= 2.17.0 < 2.21.32.21.3

CVSS provenance

nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
osv8.0HIGH
vendor_debian8.0HIGH
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.