Executive brief
Roundcube Webmail, a widely used open-source email client, contains a security flaw in how it processes incoming emails. An attacker can send a specially crafted email containing a malicious image file (SVG) to inject unauthorized styles or content into the user's browser. This could lead to the theft of sensitive information or unauthorized actions being performed on behalf of the user.
Technical details
A CSS injection vulnerability exists in Roundcube Webmail's HTML sanitizer (rcube_washtml.php). The sanitizer fails to properly neutralize SVG documents containing an <animate> element when the 'attributeName' attribute is set to 'style'. This bypass allows an attacker to inject arbitrary CSS into the webmail interface. The vulnerability is reachable over the network without authentication, typically by sending a malicious email to a victim. Successful exploitation can lead to Cross-Site Scripting (XSS) or data exfiltration. The issue is fixed in versions 1.6.16 and 1.7.1.
Affected products
- Roundcube Webmail 1.6.x before 1.6.16, 1.7.x before 1.7.1
Timeline
- 2026-05-24: patched: Security updates 1.6.16 and 1.7.1 released.
- 2026-05-25: disclosed: CVE-2026-48848 published.
References
- https://github.com/roundcube/roundcubemail/commit/58e5263f341e6a418774fb6d2643669a3c4d8a27
- https://github.com/roundcube/roundcubemail/commit/c960d102472dc579e15907d5bcdc3103a090ccf9
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.16
- https://github.com/roundcube/roundcubemail/releases/tag/1.7.1
- https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1