CVE-2025-49113
RCE CISA KEV ActiveTitle: Roundcube Webmail RCE
RCE
Proof Of Concept
PoC Available for CVE-2025-49113
CWE Category
CWE-502
Published Date
Jun 02, 2025
Modified Date
Feb 23, 2026
Exploit Status
Available
Score
9.9
CVSS v3.1
Exploit Probability (EPSS)
96.78%
Vulnerability Summary
CVE-2025-49113: Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Impacted Vendors
Reference Links
https://fearsoff.org/research/roundcube
https://github.com/roundcube/roundcubemail/commit/0376f69e958a8fef7f6f09e352c541b4e7729c4d
https://github.com/roundcube/roundcubemail/commit/7408f31379666124a39f9cb1018f62bc5e2dc695
https://github.com/roundcube/roundcubemail/commit/c50a07d88ca38f018a0f4a0b008e9a1deb32637e
https://github.com/roundcube/roundcubemail/pull/9865
https://github.com/roundcube/roundcubemail/releases/tag/1.5.10
https://github.com/roundcube/roundcubemail/releases/tag/1.6.11
https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10
https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-mitigation-script
https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-vulnerability-detection
http://www.openwall.com/lists/oss-security/2025/06/02/3
https://lists.debian.org/debian-lts-announce/2025/06/msg00008.html
CVSS v3.1
Source Entity
[email protected]
Severity
HIGH
8.8
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
Source Entity
[email protected]
Severity
CRITICAL
9.9
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
CHANGED
RAW VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2025-49113 Exploits & PoCs (Proof Of Concept)
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
CVSS Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Stack
No specific products linked.