Executive brief
Roundcube Webmail, a widely used open-source email client, is affected by a security flaw that allows attackers to execute malicious scripts in a user's browser. By sending a specially crafted email containing a malicious image file, an attacker could potentially steal session cookies, access sensitive email data, or perform actions on behalf of the user. This vulnerability is currently being exploited in the wild, making immediate updates critical for organizations using this software.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Roundcube Webmail versions prior to 1.5.12 and 1.6.x prior to 1.6.12. The flaw is rooted in the improper sanitization of SVG documents, specifically involving the 'animate' tag. An unauthenticated remote attacker can exploit this by sending a malicious email with a crafted SVG attachment or embedded content. When a user views the email, the malicious script executes within the context of the user's session. This can lead to session hijacking or unauthorized data access. The vulnerability is confirmed to be exploited in the wild and is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patches are available in versions 1.5.12 and 1.6.12.
Affected products
- Roundcube Webmail Before 1.5.12, and 1.6.x before 1.6.12
Timeline
- 2025-12-13: patched: Vendor released security updates 1.6.12 and 1.5.12
- 2025-12-18: disclosed: CVE published to NVD
- 2026-02-20: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog