Executive brief
Roundcube Webmail, a widely used open-source email client, contains a security flaw in how it handles images in emails. An attacker can send a specially crafted email that bypasses the software's privacy protections, which are designed to block remote images from loading automatically. This could allow an attacker to track when a user opens an email or potentially bypass certain access controls, compromising user privacy.
Technical details
A vulnerability in Roundcube Webmail's HTML sanitization component (rcube_washtml.php) allows attackers to bypass remote image blocking. By using SVG content containing specific 'animate' attributes within an email message, an attacker can force the webmail client to load external resources even when the user has configured the application to block remote content. This is classified as an Incorrect Resource Transfer Between Spheres (CWE-669). The issue is triggered automatically upon viewing the email without requiring further user interaction. Patches have been released in versions 1.5.14, 1.6.14, and 1.7-rc5.
Affected products
- Roundcube Webmail < 1.5.14, 1.6.x < 1.6.14
Timeline
- 2026-03-18: patched: Security updates 1.5.14 and 1.6.14 released.
- 2026-04-03: disclosed: Initial CVE publication.
References
- https://github.com/roundcube/roundcubemail/commit/1a63e01542bff42aaa71c00c4c279a09ef31f20c
- https://github.com/roundcube/roundcubemail/commit/39471343ee081ce1d31696c456a2c163462daae3
- https://github.com/roundcube/roundcubemail/commit/82ab5eca7b332fce7a174b2b987f0957a66377cd
- https://github.com/roundcube/roundcubemail/releases/tag/1.5.14
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.14
- https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc5
- https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14