Executive brief
Roundcube Webmail, a popular open-source web-based email client, contains a security flaw in how it handles email content. An attacker can send a specially crafted email that bypasses the software's privacy feature designed to block remote images. This could allow an attacker to track when a user opens an email or potentially bypass certain access controls, compromising user privacy.
Technical details
A vulnerability in Roundcube Webmail's HTML sanitization library (rcube_washtml.php) allows for a bypass of remote image blocking. By using a crafted 'background' attribute within a 'BODY' element in an HTML email, an attacker can force the client to load external resources even when the 'block remote images' setting is enabled. This is classified as an Incorrect Resource Transfer Between Spheres (CWE-669). The attack is delivered via a standard email (network vector) and requires no special privileges or user interaction beyond viewing the message. This can be used for information disclosure (e.g., tracking user IP and read status) or access-control bypass. The issue is fixed in versions 1.5.14, 1.6.14, and 1.7-rc5.
Affected products
- Roundcube Webmail < 1.5.14, 1.6.x < 1.6.14
Timeline
- 2026-03-18: patched: Security updates released in versions 1.5.14, 1.6.14, and 1.7-rc5.
- 2026-04-03: disclosed: Initial CVE publication.
References
- https://github.com/roundcube/roundcubemail/commit/e052328e3dc75f13adc2e314eaa4096ac21084ad
- https://github.com/roundcube/roundcubemail/commit/fd0e98178db5c73eaa93d005b561874923f9b0f0
- https://github.com/roundcube/roundcubemail/commit/fde14d01adc9f37893cd82b635883e516ed453f8
- https://github.com/roundcube/roundcubemail/releases/tag/1.5.14
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.14
- https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc5
- https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14