Executive brief
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk
Affected products
- Go github.com/knadh/listmonk
Junglewise Threat Intelligence
CVE-2025-49136 · Severity: low · CVSS 3.1 · Published 2025-06-10
Technologies: github.com/knadh/listmonk (Go). Vendors: Go.
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk