CVE-2025-43920
MEDIUMGNU Mailman < 2.1.39 - OS Command Injection
Title source: ruleDescription
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.
Exploits (1)
Scores
CVSS v3
5.4
EPSS
0.0137
EPSS Percentile
80.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Classification
CWE
CWE-78
Status
published
Affected Products (1)
gnu/mailman
< 2.1.39
Timeline
Published
Apr 20, 2025
Tracked Since
Feb 18, 2026