Description

In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.

INFO

Published Date :

2025-09-17T00:00:00.000Z

Last Modified :

2025-09-17T13:25:47.958Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-59518 vulnerability.

Vendors Products
Lemonldap-ng
  • Lemonldap::ng

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact