CVE 9.1 CRITICAL

mailcow: dockerized vulnerable to SSTI in Quota and Quarantine Notification Template_CVE-2025-53909

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Description

mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 2025-07 in the notification template system used by mailcow for sending quota and quarantine alerts. The template rendering engine allows template expressions that may be abused to execute code in certain contexts. The issue requires admin-level access to mailcow UI to configure templates, which are automatically rendered during normal system operation. Version 2025-07 contains a patch for the issue.

Basic Information

ID CVE-2025-53909
Source GitHub_M
Published Jul 17, 2025 at 13:47
Modified Jul 17, 2025 at 19:54

Affected Product

Vendor mailcow
Product mailcow-dockerized
Version < 2025-07
Affected Versions mailcow mailcow-dockerized < 2025-07

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.