A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
An attacker sends a specially crafted email message to the victim. When this message is displayed in the Roundcube client, a desanitization error occurs in the message_body() function located in the program/actions/mail/show.php file. As a result, malicious JavaScript code embedded in the message is executed in the victim's browser in the context of the webmail application, allowing the attacker to take control of the user's session and email operations.
An attacker can read the victim's private emails and send messages on their behalf, leading to serious breach of confidentiality and integrity of correspondence. The impact may also include further attacks based on compromised credentials or information contained in the mailbox.
Roundcube Webmail should be immediately updated to version 1.5.8 or 1.6.8, in which the vendor has made security patches available. Patches are available in vendor references: https://roundcube.net/news/2024/08/04/security-updates-1.6.8-and-1.5.8
Roundcube Webmail in versions up to and including 1.5.7 and versions 1.6.x up to and including 1.6.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NRoundcube Webmail
APPRoundcube< 1.5.81.6.0 – 1.6.8 (excl.)
CISA KEV — detailsi
- Vendori
- Roundcube
- Producti
- Webmail
- Added to KEVi
- June 9, 2025
- Remediation deadline (US Federal)i
- June 30, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
Related vulnerabilities
RCE przez deserializację PHP w Roundcube Webmail (parametr _from)
SQL Injection w Roundcube Webmail via parametry wyszukiwania
Command injection w Roundcube Webmail — RCE przez konfigurację ImageMagick
XSS w Roundcube Webmail umożliwiający kradzież i wysyłkę e-maili ofiary
Command injection w Roundcube Webmail na Windows (im_convert_path/im_identify_path)