Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-59518

25
FAUCET Score

CVE-2025-59518 describes an OS command injection vulnerability in LemonLDAP::NG versions prior to 2.16.7 and 2.21.3. This flaw allows an authenticated administrator, with the ability to edit a rule evaluated by the Safe jail, to execute arbitrary commands on the server due to improper localization during rule evaluation. Rated with a CVSS score of 8.0 (High), this vulnerability has a network attack vector, high attack complexity, and high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 2.16.7CPE match
cpe:2.3:a:lemonldap-ng:lemonldap\:\:ng:*:*:*:*:*:*:*:*
>= 2.17.0, < 2.21.3CPE match
cpe:2.3:a:lemonldap-ng:lemonldap\:\:ng:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.0HIGH

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.3
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.19%
Probability of exploitation in next 30 days
EPSS Percentile
64.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0118 is in the 80th percentile among its peer group of 81 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2025-59518Important

lemonldap-ng: OS command injection can occur in the Safe jail

Sep 17, 2025

References

gitlab.ow2.org / lemonldap-ng/lemonldap-ng/-/commit/228d01945d48015f3f9ea8a8dc64d7e6a27750e9
gitlab.ow2.org / lemonldap-ng/lemonldap-ng/issues/3462