Server-Side Template Injection Vulnerability in Mailcow by Mailcow
CVE-2025-53909
9.1CRITICAL
What is CVE-2025-53909?
Mailcow: Dockerized, an open-source groupware and email suite, is affected by a Server-Side Template Injection vulnerability found in the notification template system used for sending quota and quarantine alerts. This issue allows for template expressions that may be exploited to execute arbitrary code, necessitating admin-level access to configure templates in the Mailcow UI. The templates are processed automatically during routine system operations, increasing the threat level significantly. Users are strongly advised to upgrade to version 2025-07, which addresses this vulnerability.
Affected Version(s)
mailcow-dockerized < 2025-07