CVE-2025-59689: Libraesva Email Security Gateway Command Injection Vulnerability
Medium severity, CVSS 6.1. Actively exploited: in CISA KEV since 2025-09-29. EPSS: 1.9% chance of exploitation in the next 30 days.
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.
Affected products
- Libraesva Email Security Gateway: from 4.5, before 5.0.31 (fixed in 5.0.31); from 5.1.0, before 5.1.20 (fixed in 5.1.20); from 5.2.0, before 5.2.31 (fixed in 5.2.31); from 5.3.0, before 5.3.16 (fixed in 5.3.16); from 5.4.0, before 5.4.8 (fixed in 5.4.8); from 5.5.0, before 5.5.7 (fixed in 5.5.7)
Published 2025-09-19. Last modified 2026-06-17.