HomeSecurityVulnerability in Libraesva ESG allows injection of malicious commands

Vulnerability in Libraesva ESG allows injection of malicious commands

A critical security vulnerability in Libraesva ESG, an email security system, has been identified and patched, allowing malicious users to execute arbitrary commands via specially crafted email attachments. The vulnerability, listed as CVE-2025-59689, affects multiple versions of the popular email security platform and has already been exploited by what security researchers believe is a foreign state-sponsored threat.

See also: Fortra patches critical GoAnywhere MFT vulnerability

Libraesva ESG

The vulnerability results from improper input sanitization when removing active code from files contained in compressed file formats. When Libraesva ESG processes emails containing specially crafted compressed attachments, the security gateway fails to properly sanitize input parameters, creating an opportunity for command injection attacks.

This vulnerability affects all versions of Libraesva ESG starting with version 4.5, making it a widespread security concern for organizations that rely on the platform for their email security. The attack vector requires minimal user interaction, as the malicious payload is delivered via regular email channels.

Attackers can create compressed archives containing payload files designed to manipulate the application's sanitization logic. Once sanitization is bypassed, malicious users gain the ability to execute arbitrary shell commands under a non-privileged user account, potentially compromising the entire email security infrastructure.

See also: Popular Zero-Day vulnerabilities actively exploited in 2025

Vulnerability in Libraesva ESG allows injection of malicious commands
Vulnerability in Libraesva ESG allows injection of malicious commands

Libraesva demonstrated exceptional incident response capabilities, deploying fixes to all affected systems within 17 hours of discovery. These fixes were automatically deployed to all ESG 5.x installations via the platform’s automated update channel, ensuring full coverage for both cloud and on-premises deployments.

The remediation package included not only the core patch that addresses the sanitization vulnerability, but also automated indicators of compromise (IoCs) scanning capabilities and a self-assessment module. This comprehensive approach ensures that affected devices can verify the integrity of the patch and detect any residual threats from potential exploitation attempts.

Cloud customers received automatic updates without requiring manual intervention, while customers with on-premises version 5.x were automatically upgraded via confirmed telemetry deployments. Organizations still using version 4.x, which have reached end of support, must manually upgrade to version 5.x to be protected from this vulnerability.

See also: Warning: Critical vulnerability in the GoAnywhere MFT platform

NRD cybersecurity
Vulnerability in Libraesva ESG allows injection of malicious commands

The single confirmed exploit incident, attributed to a hostile state entity, highlights the critical nature of this security vulnerability and the importance of maintaining up-to-date software versions in email security infrastructure deployments.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS