CVE-2025-59689 is a critical command injection vulnerability affecting Libraesva ESG versions 4.5 through 5.5.x before their respective patched releases. This flaw allows unauthenticated attackers to execute arbitrary commands via specially crafted compressed email attachments, with a CVSS score of 6.1 (Medium) due to user interaction being required. Despite the medium CVSS, this vulnerability is actively exploited in the wild, including by nation-state actors, and has garnered significant community attention and media coverage. While no public exploit code is currently available on Metasploit, Nuclei, or ExploitDB, the active exploitation and high FAUCET Risk Score of 98/100 underscore its severe real-world impact. Organizations using affected Libraesva ESG versions should apply the relevant patches immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.5, < 5.0.31CPE matchmatch criteria | cpe:2.3:a:libraesva:email_security_gateway:*:*:*:*:*:*:*:* | ||
>= 5.1.0, < 5.1.20CPE matchmatch criteria | cpe:2.3:a:libraesva:email_security_gateway:*:*:*:*:*:*:*:* | ||
>= 5.2.0, < 5.2.31CPE matchmatch criteria | cpe:2.3:a:libraesva:email_security_gateway:*:*:*:*:*:*:*:* | ||
>= 5.3.0, < 5.3.16CPE matchmatch criteria | cpe:2.3:a:libraesva:email_security_gateway:*:*:*:*:*:*:*:* | ||
>= 5.4.0, < 5.4.8CPE matchmatch criteria | cpe:2.3:a:libraesva:email_security_gateway:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.