Executive brief
Roundcube Webmail, a widely used open-source web-based email client, contains a security flaw where it fails to block remote images if they point to internal or private network addresses. This could allow an attacker to send a specially crafted email that bypasses privacy settings to confirm if a user has opened a message or to probe internal network resources. Such an exploit could lead to the disclosure of sensitive internal information or potentially allow for unauthorized access to other internal systems.
Technical details
A vulnerability in the HTML sanitizer component (rcube_washtml.php) of Roundcube Webmail allows for a bypass of remote resource blocking. While the application is designed to prevent the automatic loading of remote images to protect user privacy, it fails to apply these restrictions to URLs targeting local or private network destinations. An attacker can exploit this by sending a text/html email containing embedded resources pointing to internal IP addresses or hostnames. This can result in Server-Side Request Forgery (SSRF), allowing the attacker to disclose internal information or potentially escalate privileges. The issue is fixed in versions 1.6.16 and 1.7.1.
Affected products
- Roundcube Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16; 1.7.x before 1.7.1
Timeline
- 2026-05-24: patched: Security updates 1.6.16 and 1.7.1 released.
- 2026-05-25: disclosed: CVE-2026-48845 published.
References
- https://github.com/roundcube/roundcubemail/commit/7b52353653a67e6073b97d70eb94047132b78556
- https://github.com/roundcube/roundcubemail/commit/d82b8c6cd06c378eca6d647ccd548f4ff1c68659
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.16
- https://github.com/roundcube/roundcubemail/releases/tag/1.7.1
- https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1