Vulnerability Description
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Roundcube | Webmail | < 1.5.10 |
| Debian | Debian Linux | 11.0 |
Related Weaknesses (CWE)
References
- https://fearsoff.org/research/roundcubeThird Party Advisory
- https://github.com/roundcube/roundcubemail/commit/0376f69e958a8fef7f6f09e352c541Patch
- https://github.com/roundcube/roundcubemail/commit/7408f31379666124a39f9cb1018f62Patch
- https://github.com/roundcube/roundcubemail/commit/c50a07d88ca38f018a0f4a0b008e9aPatch
- https://github.com/roundcube/roundcubemail/pull/9865Issue Tracking
- https://github.com/roundcube/roundcubemail/releases/tag/1.5.10Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.11Release Notes
- https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10Vendor Advisory
- https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-mitigation-scripExploitMitigationThird Party Advisory
- https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-vulnerability-deExploitMitigationThird Party Advisory
- http://www.openwall.com/lists/oss-security/2025/06/02/3Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/06/msg00008.htmlMailing ListThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-US Government Resource
FAQ
What is CVE-2025-49113?
CVE-2025-49113 is a vulnerability with a CVSS score of 9.9 (CRITICAL). Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php...
How severe is CVE-2025-49113?
CVE-2025-49113 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-49113?
Check the references section above for vendor advisories and patch information. Affected products include: Roundcube Webmail, Debian Debian Linux.