Executive brief
Roundcube Webmail, a widely used open-source email client, is vulnerable to a security flaw where malicious code can be hidden in email attachments. If a user views a warning page about a suspicious attachment, the hidden code could execute in their browser, potentially allowing an attacker to steal session information or perform actions on the user's behalf. Organizations should update to the latest version to protect their users' email accounts and data.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Roundcube Webmail due to improper neutralization of input during web page generation (CWE-79). Specifically, the application fails to properly escape the MIME type of an email attachment when displaying the attachment-validation warning page. An attacker can exploit this by sending a specially crafted email with a malicious MIME type string. When a recipient views the warning page associated with that attachment, the malicious script executes in the context of their session. This can lead to session hijacking or unauthorized actions. The issue is resolved in versions 1.6.17 and 1.7.2.
Affected products
- Roundcube Webmail before 1.6.17, 1.7.x before 1.7.2
Timeline
- 2026-07-05: patched: Security updates 1.6.17 and 1.7.2 released by vendor.
- 2026-07-14: disclosed: CVE published to the NVD.