Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      June 10, 2025

      How To Prevent WordPress SQL Injection Attacks

      June 10, 2025

      Development tool updates from WWDC: Foundation Models framework, Xcode 26, Swift 6.2, and more

      June 9, 2025

      Decoding The SVG path Element: Line Commands

      June 9, 2025

      Your favorite AI chatbot is lying to you all the time

      June 10, 2025

      Your CarPlay is getting a major overhaul on iOS 26: 3 new features arriving to your dashboard

      June 10, 2025

      Every iPad model that supports iPadOS 26 (and which ones won’t be compatible)

      June 10, 2025

      Why I recommend this Lenovo Android tablet to most people – especially at this price

      June 10, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Community News: Latest PECL Releases (06.10.2025)

      June 10, 2025
      Recent

      Community News: Latest PECL Releases (06.10.2025)

      June 10, 2025

      SOLID Design Principles Every JavaScript Deveveloper Should Know

      June 10, 2025

      Perficient Boldly Advances Business Through Technology Partnerships and Collaborative Innovation

      June 10, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Final Fantasy XVI launches on Xbox, and FF VII Remake Intergrade is coming this winter

      June 10, 2025
      Recent

      Final Fantasy XVI launches on Xbox, and FF VII Remake Intergrade is coming this winter

      June 10, 2025

      PowerToys Run adds Internet speed test, video downloader & more

      June 10, 2025

      Not Rumor Anymore: Persona 4 Revival Announced At Xbox Games Showcase 2025

      June 10, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-49136 – Listmonk Environment Variable Information Disclosure

    CVE-2025-49136 – Listmonk Environment Variable Information Disclosure

    June 9, 2025

    CVE ID : CVE-2025-49136

    Published : June 9, 2025, 5:15 p.m. | 4 hours, 14 minutes ago

    Description : listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to version 5.0.2, the `env` and `expandenv` template functions which is enabled by default in Sprig enables capturing of env variables on host. While this may not be a problem on single-user (super admin) installations, on multi-user installations, this allows non-super-admin users with campaign or template permissions to use the `{{ env }}` template expression to capture sensitive environment variables. Users should upgrade to v5.0.2 to mitigate the issue.

    Severity: 9.0 | CRITICAL

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-45002 – Vigybag Cross Site Scripting (XSS)
    Next Article CVE-2025-29627 – KeeperChat Biometric Authentication Module Privilege Escalation Vulnerability

    Related Posts

    Security

    Critical Wazuh bug exploited in growing Mirai botnet infection

    June 10, 2025
    Security

    The June 2025 Security Update Review

    June 10, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    How to Verify Any (Reasonable) Distribution Property: Computationally Sound Argument Systems for Distributions

    Machine Learning

    CVE-2025-26842 – Znuny S/MIME Encryption Information Disclosure Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    XSSTRON — Find XSS Vulnerabilities by Just Browsing

    Learning Resources

    Introducing Database Digest: Building Foundations for Success

    Databases

    Highlights

    News & Updates

    Can I play Clair Obscur: Expedition 33 on Steam Deck, ROG Ally, and other gaming handhelds?

    April 24, 2025

    Sandfall Interactive’s new Game Pass RPG Clair Obscur: Expedition 33 is a huge hit, but…

    The Xbox app on Windows 11 gets a handy feature just in time for the Project Kennan handheld

    May 10, 2025

    The next leap naming the future before it arrives and it’s called “India’s Human AI – Srinidhi Ranganathan

    May 11, 2025

    Love Metaphor: ReFantazio? HYTE has a new PC case and accessories for you.

    May 1, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.