Cross-Site Request Forgery and Scripting in Listmonk by Knadh
CVE-2025-58430
8.6HIGH
What is CVE-2025-58430?
Listmonk, a self-hosted newsletter and mailing list manager, contains a significant vulnerability related to session management. In versions up to and including 1.1.0, every HTTP request includes a session cookie and a nonce value which is not validated by the backend. This allows attackers to manipulate requests by removing the nonce, potentially leading to unauthorized actions. When combined with other vulnerabilities, this can facilitate serious security issues, including unauthorized admin account creation. As of the latest information, no patched versions have been released to mitigate this vulnerability.
Affected Version(s)
listmonk <= 1.1.0