Roundcube Flaw Turns Mail Logins Into Server Control
The Canadian Centre for Cyber Security says Roundcube Webmail flaw CVE-2025-49113 is being exploited in the wild, turning a May patch into an active intrusion path for internet-facing mail systems. The issue affects logged-in users of Roundcube 1.5.x and 1.6.x, with fixed releases now available in 1.5.10 and 1.6.11+.
The bug sits in how Roundcube handles trusted session input: a crafted value in a message or link path can slip past validation, so a signed-in user can trigger code execution on the mail server itself. That means the problem is not mailbox viewing alone; if attackers reach a valid account, they may be able to move from email access to server-level control.
For organizations that expose Roundcube to the internet, the lasting risk is compromised credentials, not just a vulnerable web app. If a mail host accepts user logins from weak or stolen passwords, the session can become the foothold for full compromise even after the patch is applied.
Hackers now exploit critical Roundcube flaw in code injection attacks
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.