{"id":"CVE-2025-58430","aliases":["GHSA-rf24-wg77-gq7w","GO-2025-3943"],"url":"https://o3.security/vulnerability/CVE-2025-58430","summary":"listmonk Vulnerable to CSRF to XSS Chain That Can Lead to Admin Account Takeover","details":"listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every http request in addition to the session cookie `session` there included `nonce`. The value is not checked and validated by the backend, removing `nonce` allows the requests to be processed correctly. This may seem harmless, but if chained to other vulnerabilities it can become a critical vulnerability. Cross-site request forgery and cross-site scripting chained together can result in improper admin account creation. As of time of publication, no patched versions are available.","published":"2025-09-09T19:37:45.468Z","modified":"2026-08-08T03:47:56.234326626Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/knadh/listmonk","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58430.json"},{"type":"ADVISORY","url":"https://github.com/knadh/listmonk/security/advisories/GHSA-rf24-wg77-gq7w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58430"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:47:56.234326626Z"}}