CRITICAL
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user
Published Jun 9, 2025
9.1
CRITICALCVSS 3.1
EPSS 1.54%
Description
listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to version 5.0.2, the `env` and `expandenv` template functions which is enabled by default in Sprig enables capturing of env variables on host. While this may not be a problem on single-user (super admin) installations, on multi-user installations, this allows non-super-admin users with campaign or template permissions to use the `{{ env }}` template expression to capture sensitive environment variables. Users should upgrade to v5.0.2 to mitigate the issue.
Affected products
-
- Version >= 4.0.0, < 5.0.2StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
github.com/knadh/listmonk
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/knadh/listmonk | 0 | not fixed |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/advisories/GHSA-jc7g-x28f-3v3h Advisory
- https://github.com/knadh/listmonk/commit/d27d2c32cf3af2d0b24e29ea5a686ba149b49b3e x_refsource_MISCPatch
- https://github.com/knadh/listmonk/releases/tag/v5.0.2 x_refsource_MISCRelease Notes
- https://github.com/knadh/listmonk/security/advisories/GHSA-jc7g-x28f-3v3h exploitx_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-49136
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-jc7g-x28f-3v3h | Advisory | |
| https://github.com/knadh/listmonk/commit/d27d2c32cf3af2d0b24e29ea5a686ba149b49b3e | x_refsource_MISCPatch | |
| https://github.com/knadh/listmonk/releases/tag/v5.0.2 | x_refsource_MISCRelease Notes | |
| https://github.com/knadh/listmonk/security/advisories/GHSA-jc7g-x28f-3v3h | exploitx_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-49136 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 9, 2025
Updated Jun 10, 2025
Reserved Jun 2, 2025
Link CVE-2025-49136
CISA Vulnrichment
GHSA-JC7G-X28F-3V3H Updated Jun 10, 2025