CVE-2025-49113
RoundCube Webmail Deserialization of Untrusted Data Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 13 March 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 98.90% probability · 100th percentile
- CISA KEV
- Listed 20 February 2026 · due 13 March 2026
- Weakness
- CWE-502
- Affected
- roundcube/webmail · debian/debian linux
- Source
- cve@mitre.org
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10 ; https://github.com/roundcube/roundcubemail/releases/tag/1.5.10 ; https://github.com/roundcube/roundcubemail/releases/tag/1.6.11 ; https://nvd.nist.gov/vuln/detail/CVE-2025-49113
References
- https://fearsoff.org/research/roundcubeThird Party Advisory
- https://github.com/roundcube/roundcubemail/commit/0376f69e958a8fef7f6f09e352c541b4e7729c4dPatch
- https://github.com/roundcube/roundcubemail/commit/7408f31379666124a39f9cb1018f62bc5e2dc695Patch
- https://github.com/roundcube/roundcubemail/commit/c50a07d88ca38f018a0f4a0b008e9a1deb32637ePatch
- https://github.com/roundcube/roundcubemail/pull/9865Issue Tracking
- https://github.com/roundcube/roundcubemail/releases/tag/1.5.10Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.11Release Notes
- https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10Vendor Advisory
- https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-mitigation-scriptExploit, Mitigation, Third Party Advisory
- https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-vulnerability-detectionExploit, Mitigation, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2025/06/02/3Mailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/06/msg00008.htmlMailing List, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-49113US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.