VYPR

Lemonldap Ng

by Lemonldap Ng

Source repositories

CVEs (1)

  • CVE-2025-59518HigSep 17, 2025
    risk 0.45cvss 8.0epss 0.00

    In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.