Junglewise Threat Intelligence

CVE-2026-35545: Roundcube Webmail remote image blocking bypass in SVG content

CVE-2026-35545 · Severity: medium · CVSS 5.3 · Published 2026-04-03

Technologies: roundcube/roundcubemail (Packagist), Roundcube Webmail. Vendors: Packagist, Roundcube.

Executive brief

Roundcube Webmail, a widely used open-source email client, is vulnerable to a security bypass that allows remote images to load even when the user has blocked them. By sending a specially crafted email containing specific SVG image elements, an attacker can track when a user opens an email or potentially bypass certain access controls. This can lead to unauthorized information disclosure, such as confirming a user's IP address and active status to a malicious sender.

Technical details

A vulnerability exists in Roundcube Webmail's HTML sanitization engine (rcube_washtml.php) where the remote image blocking feature can be bypassed. The flaw involves the 'animate' element within SVG content using 'fill', 'filter', or 'stroke' attributes. By utilizing Functional Internal Reference Identifiers (FUNCIRI) within these attributes, an attacker can force the webmail client to load external resources without user consent. This bypass allows for unauthorized remote image loading, which can be used for tracking or information disclosure. Patches have been released in versions 1.5.15, 1.6.15, and 1.7-rc6.

Affected products

  • Roundcube Webmail < 1.5.15, 1.6.0 < 1.6.15, 1.7-rc < 1.7-rc6

Timeline

  • 2026-03-29: patched: Security updates 1.5.15, 1.6.15, and 1.7-rc6 released
  • 2026-04-03: disclosed: CVE-2026-35545 published

References

Related threats