CVE-2025-59689
9.5 CISA KEVLibraesva · Email Security Gateway
Libraesva Email Security Gateway (ESG) is vulnerable to command injection via specially crafted compressed email attachments, allowing unauthorized execution of shell commands.
Executive summary
This critical command injection vulnerability in Libraesva Email Security Gateway is currently being exploited in the wild and requires immediate remediation to prevent unauthorized system access.
Vulnerability
This flaw involves improper neutralization of special elements during the processing of compressed email attachments. An attacker can trigger command injection by sending a specially crafted attachment, allowing shell commands to execute under a non-privileged user context.
Business impact
With a CVSS score of 9.5, this vulnerability represents a critical risk to organizational security. Successful exploitation allows an attacker to execute arbitrary commands on the gateway, potentially leading to full system compromise, data exfiltration, or the interception of sensitive communications. The active exploitation of this vulnerability in the wild, including targeted attacks by sophisticated actors, significantly elevates the risk to business continuity and data integrity.
Remediation
Immediate Action: Update your Libraesva Email Security Gateway to the following versions immediately: 5.0.31, 5.1.20, 5.2.31, 5.3.16, 5.4.8, or 5.5.7.
Proactive Monitoring: Review system logs for unusual process execution patterns or unexpected shell commands originating from the email processing service.
Compensating Controls: While patching is the only definitive fix, ensure that perimeter email filtering policies are configured to block suspicious or malformed compressed archive attachments as a temporary defensive measure.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical severity and confirmed active exploitation of this flaw, immediate patching is mandatory. Administrators must prioritize applying the provided updates to all affected Libraesva Email Security Gateway instances without delay. Failure to remediate this vulnerability leaves the organization exposed to targeted attacks and potential system compromise.