CVE-2025-49113

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

22 Dec 2025, 18:00

Type Values Removed Values Added
CPE cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
First Time Roundcube
Debian debian Linux
Roundcube webmail
Debian
References () https://fearsoff.org/research/roundcube - () https://fearsoff.org/research/roundcube - Third Party Advisory
References () https://github.com/roundcube/roundcubemail/commit/0376f69e958a8fef7f6f09e352c541b4e7729c4d - () https://github.com/roundcube/roundcubemail/commit/0376f69e958a8fef7f6f09e352c541b4e7729c4d - Patch
References () https://github.com/roundcube/roundcubemail/commit/7408f31379666124a39f9cb1018f62bc5e2dc695 - () https://github.com/roundcube/roundcubemail/commit/7408f31379666124a39f9cb1018f62bc5e2dc695 - Patch
References () https://github.com/roundcube/roundcubemail/commit/c50a07d88ca38f018a0f4a0b008e9a1deb32637e - () https://github.com/roundcube/roundcubemail/commit/c50a07d88ca38f018a0f4a0b008e9a1deb32637e - Patch
References () https://github.com/roundcube/roundcubemail/pull/9865 - () https://github.com/roundcube/roundcubemail/pull/9865 - Issue Tracking
References () https://github.com/roundcube/roundcubemail/releases/tag/1.5.10 - () https://github.com/roundcube/roundcubemail/releases/tag/1.5.10 - Release Notes
References () https://github.com/roundcube/roundcubemail/releases/tag/1.6.11 - () https://github.com/roundcube/roundcubemail/releases/tag/1.6.11 - Release Notes
References () https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10 - () https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10 - Vendor Advisory
References () https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-mitigation-script - () https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-mitigation-script - Exploit, Mitigation, Third Party Advisory
References () https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-vulnerability-detection - () https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-vulnerability-detection - Exploit, Mitigation, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2025/06/02/3 - () http://www.openwall.com/lists/oss-security/2025/06/02/3 - Mailing List, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2025/06/msg00008.html - () https://lists.debian.org/debian-lts-announce/2025/06/msg00008.html - Mailing List, Third Party Advisory

12 Jun 2025, 17:15

Type Values Removed Values Added
References
  • () https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-mitigation-script -
  • () https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-vulnerability-detection -

09 Jun 2025, 04:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/06/msg00008.html -
Summary
  • (es) Roundcube Webmail anterior a 1.5.10 y 1.6.x anterior a 1.6.11 permite la ejecución remota de código por parte de usuarios autenticados porque el parámetro _from en una URL no está validado en program/actions/settings/upload.php, lo que lleva a la deserialización de objetos PHP.

02 Jun 2025, 18:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/06/02/3 -

02 Jun 2025, 13:15

Type Values Removed Values Added
References
  • () https://fearsoff.org/research/roundcube -

02 Jun 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-02 05:15

Updated : 2025-12-22 18:00


NVD link : CVE-2025-49113

Mitre link : CVE-2025-49113

CVE.ORG link : CVE-2025-49113


JSON object : View

Products Affected

roundcube

  • webmail

debian

  • debian_linux
CWE
CWE-502

Deserialization of Untrusted Data