CVE-2025-43920

MEDIUM

GNU Mailman < 2.1.39 - OS Command Injection

Title source: rule

Description

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

Exploits (1)

nomisec WRITEUP 1 stars
by 0NYX-MY7H · poc
https://github.com/0NYX-MY7H/CVE-2025-43920

Scores

CVSS v3 5.4
EPSS 0.0137
EPSS Percentile 80.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

Classification

CWE
CWE-78
Status published

Affected Products (1)

gnu/mailman < 2.1.39

Timeline

Published Apr 20, 2025
Tracked Since Feb 18, 2026