CVE-2025-49113
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload....
Description
Roundcube Webmail Vulnerable to Authenticated RCE via PHP Object Deserialization
In plain language
AI Act nowCVE-2025-49113 is a RoundCube Webmail flaw that lets a logged-in attacker run code on your email server; if you use an affected RoundCube Webmail version, this is a serious, urgent problem.
CVE-2025-49113 is an authenticated remote code execution flaw in RoundCube Webmail caused by insufficient validation of the URL “_from” parameter, enabling attackers to trigger server-side code execution; it is listed in CISA KEV and has a remediation due date.
What to do now
- Check your RoundCube Webmail version and confirm whether it is earlier than 1.5.10 or (for the 1.6 line) earlier than 1.6.11.
- Upgrade RoundCube Webmail to 1.5.10 (if you are on the 1.5 branch) or to 1.6.11 (if you are on the 1.6 branch).
- If you cannot upgrade immediately, apply the vendor/workaround mitigation steps for CVE-2025-49113 and restrict who can access the webmail login.
- Review web server and RoundCube logs for unusual actions from authenticated webmail users around the time of any suspicious activity.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacksen·The Hacker News· Exploited Notepad++ UAC-0099
- Уязвимости в Roundcube используются для слежки за ученымиru-ru·Хакер (xakep.ru)· Exploited Roundcube Webmail UNK_MassTraction
- Hackers exploit Roundcube flaw to spy on academic researchersen-us·BleepingComputer· Exploited Roundcube UNK_MassTraction
- Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universitiesen·The Hacker News· Exploited Roundcube webmail UNK_MassTraction
- Киберугрозы 2025-2026: какие уязвимости были и будут в трендеru·Positive Technologies (Хабр)· Roundup rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-49113 and every CVE in our database. Create a free account — no credit card required.
Create Free Account