Script Code Execution Vulnerability in Open-Xchange Products
CVE-2025-59025

6.1MEDIUM

Key Information:

Vendor
CVE Published:
27 November 2025

What is CVE-2025-59025?

A vulnerability in Open-Xchange Appsuite enables the execution of script code via malicious email content. Users may unknowingly carry out unintended actions within their accounts, which could lead to the exfiltration of sensitive information. To address this issue, sanitization measures have been updated in the platform. Currently, no publicly available exploits are known, but users are advised to remain vigilant.

Affected Version(s)

OX App Suite 0 <= 8.35.110

OX App Suite 0 <= 8.39.85

OX App Suite 0 <= 8.40.73

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.