Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59689.json"
[
{
"events": [
{
"introduced": "4.5"
},
{
"fixed": "5.0.31"
}
]
},
{
"events": [
{
"introduced": "5.1.0"
},
{
"fixed": "5.1.20"
}
]
},
{
"events": [
{
"introduced": "5.2.0"
},
{
"fixed": "5.2.31"
}
]
},
{
"events": [
{
"introduced": "5.3.0"
},
{
"fixed": "5.3.16"
}
]
},
{
"events": [
{
"introduced": "5.4.0"
},
{
"fixed": "5.4.8"
}
]
},
{
"events": [
{
"introduced": "5.5.0"
},
{
"fixed": "5.5.7"
}
]
}
]