SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-59689

Libraesva Email Security Gateway Command Injection Vulnerability

KEVMEDIUM 6.1EPSS 1.86%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 20 October 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
1.86% probability · 78th percentile
CISA KEV
Listed 29 September 2025 · due 20 October 2025
Weakness
CWE-77
Affected
libraesva/email security gateway
Source
cve@mitre.org

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://docs.libraesva.com/knowledgebase/security-advisory-command-injection-vulnerability-cve-2025-59689/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-59689

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.