CVE-2025-59518: OS Command Injection
In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59518?
CVE-2025-59518 is considered a high severity vulnerability due to the potential for OS command injection.
How do I fix CVE-2025-59518?
To fix CVE-2025-59518, upgrade LemonLDAP::NG to version 2.21.3 or later.
What versions of LemonLDAP::NG are affected by CVE-2025-59518?
CVE-2025-59518 affects LemonLDAP::NG versions prior to 2.16.7 and from 2.17 up to 2.21 excluding 2.21.3.
What kind of attack can occur due to CVE-2025-59518?
CVE-2025-59518 allows an attacker to perform OS command injection through editable rules in the Safe jail.
Who is at risk from CVE-2025-59518?
Administrators with the ability to edit rules evaluated by the Safe jail in LemonLDAP::NG are at risk from CVE-2025-59518.