Server-Side Template Injection Vulnerability in Mailcow by Mailcow
CVE-2025-53909

9.1CRITICAL

Key Information:

Vendor

Mailcow

Vendor
CVE Published:
17 July 2025

What is CVE-2025-53909?

Mailcow: Dockerized, an open-source groupware and email suite, is affected by a Server-Side Template Injection vulnerability found in the notification template system used for sending quota and quarantine alerts. This issue allows for template expressions that may be exploited to execute arbitrary code, necessitating admin-level access to configure templates in the Mailcow UI. The templates are processed automatically during routine system operations, increasing the threat level significantly. Users are strongly advised to upgrade to version 2025-07, which addresses this vulnerability.

Affected Version(s)

mailcow-dockerized < 2025-07

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53909 : Server-Side Template Injection Vulnerability in Mailcow by Mailcow