CVE List

CVE-2025-43920

Critical 8.1

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line.

Published April 20, 2025.

Affected software

Get alerts for Gnu Mailman

Reference links