CVE-2025-59518
published 2025-09-17CVE-2025-59518: In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule…
PriorityP353high8CVSS 3.1
AVNACHPRHUINSCCHIHAH
EPSS
1.19%
64.5th percentile
In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lemonldap-ng | < lemonldap-ng 2.16.1+ds-deb12u7 (bookworm) | lemonldap-ng 2.16.1+ds-deb12u7 (bookworm) |
| lemonldap-ng | lemonldap_ng | < 2.16.7 | 2.16.7 |
| lemonldap-ng | lemonldap_ng | >= 2.17.0 < 2.21.3 | 2.21.3 |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
osv8.0HIGH
vendor_debian8.0HIGH
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
lemonldap-ng: OS command injection can occur in the Safe jail
vendor_redhat·2025-09-17·CVSS 8.0
CVE-2025-59518 [HIGH] CWE-78 lemonldap-ng: OS command injection can occur in the Safe jail
lemonldap-ng: OS command injection can occur in the Safe jail
In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.
A OS command injection found in lemonldap-ng that can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.
Statement: This is a Important vulnerability because it breaks the Safe jail’s sandboxing by allowing OS command injection via the Perl _ variable. An admin can exploit this to execute arbitrary commands on the server, leading to full
Debian
CVE-2025-59518: lemonldap-ng - In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command i...
vendor_debian·2025·CVSS 8.0
CVE-2025-59518 [HIGH] CVE-2025-59518: lemonldap-ng - In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command i...
In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.
Scope: local
bookworm: resolved (fixed in 2.16.1+ds-deb12u7)
bullseye: open
forky: resolved (fixed in 2.21.3+ds-1)
sid: resolved (fixed in 2.21.3+ds-1)
trixie: resolved (fixed in 2.21.2+ds-1+deb13u1)
GHSA
GHSA-fxqv-qm7m-363x: In LemonLDAP::NG before 2
ghsa_unreviewed·2025-09-17
CVE-2025-59518 [HIGH] CWE-78 GHSA-fxqv-qm7m-363x: In LemonLDAP::NG before 2
In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.
OSV
CVE-2025-59518: In LemonLDAP::NG before 2
osv·2025-09-17·CVSS 8.0
CVE-2025-59518 [HIGH] CVE-2025-59518: In LemonLDAP::NG before 2
In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-09-17
Published