CVE-2025-49113
Roundcube Webmail
Published 2 Jun 2025 · updated 17 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 20 Feb 2026, with a remediation deadline of 13 Mar 2026 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
References
- fearsoff.org/research/roundcube · Third Party Advisory
- github.com/roundcube/roundcubemail/commit/0376f69e958a8fef7f6f09e352c541b4e7729c4d · Patch
- github.com/roundcube/roundcubemail/commit/7408f31379666124a39f9cb1018f62bc5e2dc695 · Patch
- github.com/roundcube/roundcubemail/commit/c50a07d88ca38f018a0f4a0b008e9a1deb32637e · Patch
- github.com/roundcube/roundcubemail/pull/9865 · Issue Tracking
- github.com/roundcube/roundcubemail/releases/tag/1.5.10 · Release Notes
- github.com/roundcube/roundcubemail/releases/tag/1.6.11 · Release Notes
- roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10 · Vendor Advisory
- www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-mitigation-script · Exploit, Mitigation, Third Party Advisory
- www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-vulnerability-detection · Exploit, Mitigation, Third Party Advisory
- www.openwall.com/lists/oss-security/2025/06/02/3 · Mailing List, Third Party Advisory
- lists.debian.org/debian-lts-announce/2025/06/msg00008.html · Mailing List, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-49113 · US Government Resource