CVE-2025-59518
17.09.2025, 04:16
In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.
Awaiting analysis
This vulnerability is currently awaiting analysis.

Debian Releases