CVE-2025-49136
listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to version 5.0.2, the `env` and `expandenv` template functions which is enabled by default in Sprig enables capturing of env variables on host. While this may not be a problem on single-user (super admin) installations, on multi-user installations, this allows non-super-admin users with campaign or template permissions to use the `{{ env }}` template expression to capture sensitive environment variables. Users should upgrade to v5.0.2 to mitigate the issue.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- EPSS probability
- 1.44%
- CWE
- CWE-1336
- Published
- 2025-06-09
- Last modified
- 2026-03-13
Affected products
- knadh listmonk
Weakness type
Related vulnerabilities
- CVE-2026-89094 — Forgejo before 16.0.4 allows remote code execution via a crafted template repository because...
- CVE-2026-19584 — Velociraptor VQL injection during notebook restore from backup
- CVE-2026-87021 — Tanium addressed an unauthorized code execution vulnerability in Comply.
- CVE-2026-33387 — Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0
- CVE-2026-75650 — Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
- CVE-2026-52762 — YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates
- CVE-2026-46636 — Twig: Sandbox method allowlist bypass via `Markup` subclass
- CVE-2026-85654 — Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server