Impact
A Server-Side Template Injection (SSTI) vulnerability exists in the notification template system used by mailcow for sending quota and quarantine alerts. The template rendering engine allows template expressions that may be abused to execute code in certain contexts.
The issue requires admin-level access to mailcow UI to configure templates, which are automatically rendered during normal system operation.
Patches
Stable: 2025-07
Legacy: 8c5f6c0
Credits
Natalia Baranova from Selectel
Impact
A Server-Side Template Injection (SSTI) vulnerability exists in the notification template system used by mailcow for sending quota and quarantine alerts. The template rendering engine allows template expressions that may be abused to execute code in certain contexts.
The issue requires admin-level access to mailcow UI to configure templates, which are automatically rendered during normal system operation.
Patches
Stable: 2025-07
Legacy: 8c5f6c0
Credits
Natalia Baranova from Selectel