0NYX-MY7H/CVE-2025-43919

0NYX-MY7H/CVE-2025-43919

Releases0
CVE-2025-43919: Directory Traversal Vulnerability in GNU Mailman 2.1.39

CVE History

CVEPublishedCVSS v3CVSS v2
5.8 MEDIUM

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.