PT-2025-23462 · Unknown +4 · Roundcube Webmail +4

Firs0V

·

Published

2025-06-01

·

Updated

2025-08-30

·

CVE-2025-49113

CVSS v3.1
9.9
VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions:**

Roundcube versions 1.1.0 through 1.6.10

**Description:**

Roundcube Webmail contains a PHP Object Deserialization vulnerability in the ` from` parameter within a URL, potentially allowing a remote attacker to execute arbitrary code. This vulnerability affects authenticated users. Exploitation has been observed in the wild, with proof-of-concept exploits publicly available. Over 84,000 systems are estimated to be vulnerable. The vulnerability stems from a lack of input validation during the deserialization process.

**Recommendations:**

Update Roundcube to version 1.5.10 or 1.6.11, or later.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-06366
CVE-2025-49113
DLA-4211-1
DSA-5934-1
GHSA-8J8W-WWQC-X596
MGASA-2025-0185
USN-7584-1

Affected Products

Debian
Linuxmint
Red Os
Roundcube Webmail
Ubuntu