← Back to browse · API

CVE-2025-59689

Severity
MEDIUM
CVSS
6.1
EPSS
0.01913
Risk score
50.07
CISA KEV
Yes
PoC
No
Published
2025-09-19
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-30249, GHSA-363H-22W6-HCRM
Products
Libraesva:Email Security Gateway, Libraesva:Email Security Gateway 4.5 <5.0.31, Libraesva:Email Security Gateway 5.1 <5.1.20, Libraesva:Email Security Gateway 5.2 <5.2.31, Libraesva:Email Security Gateway 5.3 <5.4.8, Libraesva:Email Security Gateway 5.5 <5.5.7
Sources
cisa.gov CVE-2025-59689
euvd EUVD-2025-30249

Description

Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.

References