← Back

CVE-2025-43920

nvd nist
Published: Apr 20, 2025Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

Affected (1)

Products: Gnu: Mailman
1 product
Mailman
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.1.1 to 2.1.39

References (4)

Timeline

No history available yet.