Vulnerability record · CVE-2025-59689 · published 19 September 2025
CVE-2025-59689: Libraesva ESG command injection via compressed email attachment
Libraesva · Email Security Gateway
Libraesva Email Security Gateway versions 4.5 through 5.5.x before 5.5.7 are vulnerable to command injection triggered by a compressed email attachment. Because the gateway processes inbound mail, a crafted attachment can execute commands on the appliance itself, which sits directly in the mail path. The vendor has released fixed builds for each affected branch.
Description
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityThe flaw is remotely reachable through email and listed in CISA KEV as exploited, though the CVSS score is only medium and user interaction is required.
What it is
Libraesva Email Security Gateway versions 4.5 through 5.5.x before 5.5.7 are vulnerable to command injection triggered by a compressed email attachment. Because the gateway processes inbound mail, a crafted attachment can execute commands on the appliance itself, which sits directly in the mail path. The vendor has released fixed builds for each affected branch.
Impact
An attacker who gets a crafted compressed attachment delivered can execute arbitrary commands on the ESG appliance, potentially compromising the mail gateway and any credentials or mail content it handles. The CVSS vector limits rated impact to low confidentiality and integrity with no availability loss, so the practical blast radius depends on the appliance's privileges and network position.
Attack surface
Reached remotely over the network through email delivery of a malicious compressed attachment; no authentication is required, but the CVSS vector requires user interaction, meaning a recipient or mail-processing action must trigger handling of the attachment.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2025-09-29 with a 2025-10-20 remediation due date, indicating known exploitation in the wild. EPSS is low at roughly 1.9 percent (78th percentile), and no ransomware campaign use is documented.
What to do
- Upgrade to the fixed build for your branch: 5.0.31, 5.1.20, 5.2.31, 5.4.8, or 5.5.7, or later.
- If patching cannot be completed by the CISA due date, apply the vendor's documented mitigations or discontinue use of the product per BOD 22-01 guidance.
- Restrict management and outbound network access from the ESG appliance so injected commands have limited reach.
- Block or quarantine compressed attachment types at the perimeter until all instances are confirmed patched.
Detection
- Monitor ESG appliance logs and process telemetry for unexpected child processes spawned by mail-handling services.
- Alert on outbound connections from the ESG appliance to unfamiliar hosts, which may indicate post-exploitation activity.
- Search mail logs for compressed attachments that correlate in time with anomalous command execution or process creation on the gateway.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-59689 to the Known Exploited Vulnerabilities catalog on 29 September 2025 as "Libraesva Email Security Gateway Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 20 October 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://docs.libraesva.com/knowledgebase/security-advisory-command-injection-vulnerability-cve-2025-59689/ | Vendor Advisory |
| https://www.libraesva.com/security-blog/ | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59689 | US Government Resource |
Track CVE-2025-59689 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-59689), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.