CVE-2025-49136 is a medium-severity vulnerability affecting listmonk versions 4.0.0 through 5.0.1, where insecure template functions allow non-super-admin users with specific permissions to disclose sensitive environment variables. This flaw has a CVSS score of 6.5 (Medium) with low attack complexity and high confidentiality impact, accessible over the network. Although not currently listed in CISA KEV, it is on the "Hot List" and has a high EPSS score, indicating a significant likelihood of exploitation. A Metasploit module is available, providing readily usable exploit code, yet community discussion and media coverage remain minimal. Users are advised to upgrade to version 5.0.2 to mitigate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 5.0.2CPE matchmatch criteria | cpe:2.3:a:nadh:listmonk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.