CVE-2025-43919 describes a directory traversal vulnerability in GNU Mailman 2.1.39, specifically as bundled in cPanel and WHM, allowing unauthenticated attackers to read arbitrary files. The flaw, located at the /mailman/private/mailman endpoint, can be exploited via the username parameter. With a CVSS score of 7.5 (HIGH), this vulnerability presents a low-complexity network attack vector that could lead to high confidentiality impact without requiring user interaction. Despite its severity, multiple third parties report difficulty reproducing the issue, and there is currently no public exploit code, Metasploit module, or significant community discussion or media coverage, suggesting it is not actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.1.1, <= 2.1.39CPE matchmatch criteria | cpe:2.3:a:gnu:mailman:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.