Cross-Site Request Forgery and Scripting in Listmonk by Knadh
CVE-2025-58430
What is CVE-2025-58430?
Listmonk, a self-hosted newsletter and mailing list manager, contains a significant vulnerability related to session management. In versions up to and including 1.1.0, every HTTP request includes a session cookie and a nonce value which is not validated by the backend. This allows attackers to manipulate requests by removing the nonce, potentially leading to unauthorized actions. When combined with other vulnerabilities, this can facilitate serious security issues, including unauthorized admin account creation. As of the latest information, no patched versions have been released to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
listmonk <= 1.1.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
