Executive brief
Libraesva Email Security Gateway, a solution used to filter and protect corporate email traffic, is vulnerable to a security flaw that allows attackers to execute unauthorized commands. By sending a specially crafted compressed email attachment, an attacker can compromise the gateway. This vulnerability has been observed being used in active attacks, potentially leading to unauthorized access or disruption of email services.
Technical details
A command injection vulnerability (CWE-77) exists in Libraesva ESG versions 4.5 through 5.5.x. The flaw is triggered when the gateway processes a specially crafted compressed email attachment. An unauthenticated remote attacker can exploit this by sending a malicious email to a user protected by the gateway, leading to arbitrary command execution on the underlying operating system. This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. Patches have been released for various major versions, including 5.0.31, 5.1.20, 5.2.31, 5.4.8, and 5.5.7.
Affected products
- Libraesva Email Security Gateway (ESG) 4.5 through 5.5.x before 5.5.7 (specifically: < 5.0.31, < 5.1.20, < 5.2.31, < 5.4.8, < 5.5.7)
Timeline
- 2025-09-19: disclosed: Initial CVE publication
- 2025-09-29: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-09-29: advisory: Vendor security advisory published