Security Advisory

CVE-2025-59518

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-09-17 00:00:00
Last updated 2026-05-11 08:38:41
Assigner mitre
CVSS score 8.0
State PUBLISHED

Description

In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.