CVE-2025-43919: medium-severity vulnerability in GNU Mailman
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.8epss 1.4%
exploitation probability
1.4%top 29% of all CVEs
observed exploitation
nono source reports it
In short
GNU Mailman 2.1.39 in cPanel/WHM allows anyone to read private files by using path traversal tricks in the login form. An attacker can bypass authentication and access files they shouldn't see.
Technical detail
A path traversal vulnerability exists in the private archive authentication endpoint (/mailman/private/mailman) where the username parameter fails to properly sanitize ../ sequences, allowing unauthenticated attackers to read arbitrary files. The attack requires no authentication and exploits improper input validation, though reproducibility varies across configurations.
Summary generated and translated by AI from the official description.
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Affected products
GNU · MailmanRelated CVEs — GNU Mailman
In the same product, most dangerous first.