listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to version 5.0.2, the `env` and `expandenv` template functions which is enabled by default in Sprig enables capturing of env variables on host. While this may not be a problem on single-user (super admin) installations, on multi-user installations, this allows non-super-admin users with campaign or template permissions to use the `{{ env }}` template expression to capture sensitive environment variables. Users should upgrade to v5.0.2 to mitigate the issue.
History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00037}

epss

{'score': 0.00031}


Fri, 11 Jul 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Nadh
Nadh listmonk
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:nadh:listmonk:*:*:*:*:*:*:*:*
Vendors & Products Nadh
Nadh listmonk

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00032}

epss

{'score': 0.00037}


Tue, 10 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 09 Jun 2025 16:30:00 +0000

Type Values Removed Values Added
Description listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to version 5.0.2, the `env` and `expandenv` template functions which is enabled by default in Sprig enables capturing of env variables on host. While this may not be a problem on single-user (super admin) installations, on multi-user installations, this allows non-super-admin users with campaign or template permissions to use the `{{ env }}` template expression to capture sensitive environment variables. Users should upgrade to v5.0.2 to mitigate the issue.
Title listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user
Weaknesses CWE-1336
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-09T16:21:48.266Z

Updated: 2025-06-10T13:25:02.262Z

Reserved: 2025-06-02T10:39:41.634Z

Link: CVE-2025-49136

cve-icon Vulnrichment

Updated: 2025-06-10T13:24:51.733Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-09T17:15:29.917

Modified: 2025-07-11T17:23:30.110

Link: CVE-2025-49136

cve-icon Redhat

No data.