{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-01T17:57:43.288","vulnerabilities":[{"cve":{"id":"CVE-2025-53909","sourceIdentifier":"security-advisories@github.com","published":"2025-07-17T14:15:32.213","lastModified":"2025-09-11T20:16:06.607","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 2025-07 in the notification template system used by mailcow for sending quota and quarantine alerts. The template rendering engine allows template expressions that may be abused to execute code in certain contexts. The issue requires admin-level access to mailcow UI to configure templates, which are automatically rendered during normal system operation. Version 2025-07 contains a patch for the issue."},{"lang":"es","value":"mailcow: dockerized es una suite de correo electrónico/groupware de código abierto basada en Docker. Existe una vulnerabilidad de inyección de plantillas del lado del servidor (SSTI) en versiones anteriores a la 2025-07 en el sistema de plantillas de notificación que mailcow utiliza para enviar alertas de cuota y cuarentena. El motor de renderizado de plantillas permite que expresiones de plantilla que podrían ser utilizadas indebidamente ejecuten código en ciertos contextos. El problema requiere acceso de administrador a la interfaz de usuario de mailcow para configurar las plantillas, que se renderizan automáticamente durante el funcionamiento normal del sistema. La versión 2025-07 contiene un parche para solucionar el problema."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1336"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mailcow:mailcow\\:_dockerized:*:*:*:*:*:*:*:*","versionEndExcluding":"2025-07","matchCriteriaId":"8DE8467A-C5F8-40C3-B411-B9F4BCED7E7E"}]}]}],"references":[{"url":"https://github.com/mailcow/mailcow-dockerized/commit/8c5f6c03214a4b2bdbf3c78932f860eee949012b","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-8p7g-6cjj-wr9m","source":"security-advisories@github.com","tags":["Vendor Advisory"]}]}}]}