cve/2025/CVE-2025-59518.md
2025-09-29 21:09:30 +02:00

990 B

CVE-2025-59518

Description

In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.

POC

Reference

No PoCs from references.

Github