CVE-2025-59518: Lemonldap-NG Lemonldap::ng

High severity, CVSS 8.0. EPSS: 1.2% chance of exploitation in the next 30 days.

In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.

Affected products

  • Lemonldap-NG Lemonldap::ng: before 2.16.7 (fixed in 2.16.7); from 2.17.0, before 2.21.3 (fixed in 2.21.3)

Published 2025-09-17. Last modified 2026-06-17.