CVE-2025-49113

high

Description

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

References

https://securityaffairs.com/197098/uncategorized/north-korean-lazarus-group-uses-windows-zero-day-in-operation-dream-job.html

https://www.securityweek.com/fresh-windows-zero-day-exploited-in-north-korean-cyberattacks/

https://www.infosecurity-magazine.com/news/lazarus-post-quantum-key-dream-job/

https://www.helpnetsecurity.com/2026/08/12/north-korea-lazarus-fake-job-offers/

https://www.bleepingcomputer.com/news/security/lazarus-hackers-exploited-windows-zero-day-to-target-defense-firms/

https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html

https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/

https://blog.checkpoint.com/research/state-sponsored-hackers-use-fake-job-offers-to-deliver-new-zero-day-exploit/

https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html

https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits

https://www.theregister.com/security/2026/07/08/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers/5268778

https://www.bleepingcomputer.com/news/security/hackers-exploit-roundcube-flaw-to-spy-on-academic-researchers/

https://hackread.com/unk-masstraction-roundcube-us-canada-universities/

https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation

https://www.infosecurity-magazine.com/news/china-aligned-cluster-roundcube/

https://www.databreachtoday.com/chinese-cyberespionage-exploits-university-roundcube-servers-a-32165

https://thehackernews.com/2026/07/suspected-china-aligned-hackers-exploit.html

https://cyberscoop.com/china-espionage-attacks-us-canada-universities-proofpoint/

https://www.securityweek.com/recent-roundcube-webmail-vulnerability-exploited-in-attacks/

https://www.bleepingcomputer.com/news/security/cisa-recently-patched-roundcube-flaws-now-exploited-in-attacks/

https://thehackernews.com/2026/02/cisa-adds-two-actively-exploited.html

https://securityaffairs.com/188324/security/u-s-cisa-adds-roundcube-webmail-flaws-to-its-known-exploited-vulnerabilities-catalog.html

https://www.cisa.gov/news-events/alerts/2026/02/20/cisa-adds-two-known-exploited-vulnerabilities-catalog

https://securityaffairs.com/183222/apt/ukraine-sees-surge-in-ai-powered-cyberattacks-by-russia-linked-threat-actors.html

https://www.bleepingcomputer.com/news/security/hacker-steals-1-million-cockli-user-records-in-webmail-data-breach/

https://securityaffairs.com/178887/hacking/over-80000-servers-hit-as-roundcube-rce-bug-gets-rapidly-exploited.html

https://www.securityweek.com/exploited-vulnerability-impacts-over-80000-roundcube-servers/

https://www.bleepingcomputer.com/news/security/hacker-selling-critical-roundcube-webmail-exploit-as-tech-info-disclosed/

https://github.com/shunfeng8421/exploit-library

https://github.com/diedromeo/CVE-Labs-2025-2026

https://github.com/shunfeng8421/security-audit

https://github.com/smadonkuan/CVE-LAb

https://github.com/ZeroTrustWraith/Exploit-PoC

https://github.com/mooder1/CVE-2025-49113

https://github.com/Lucas-Cyber-Security/CVE_Projects

https://github.com/ankitpandey383/roundcube-cve-2025-49113-lab

https://github.com/bj715/TDCVES

https://github.com/V0idA2tronaut/CVEs

https://github.com/ynvk404/cve-research

https://github.com/l4f2s4/CVE-2025-49113_exploit_cookies

https://github.com/Zuack55/Roundcube-1.6.10-Post-Auth-RCE-CVE-2025-49113-

https://github.com/Leonideath/nuclei-cve-crit-high

https://github.com/LeakForge/CVE-2025-49113

https://github.com/AC8999/CVE-2025-49113

https://github.com/SteamPunk424/CVE-2025-49113-Roundcube-RCE-PHP

https://github.com/CyberQuestor-infosec/CVE-2025-49113-Roundcube_1.6.10

https://github.com/a-s-m-asadujjaman/exploitables

https://github.com/Joelp03/CVE-2025-49113

https://github.com/hackmelocal/CVE-2025-49113-Simulation

https://github.com/issamjr/CVE-2025-49113-Scanner

https://github.com/SyFi/CVE-2025-49113

https://github.com/Ademking/CVE-2025-49113-nuclei-template

https://github.com/rxerium/CVE-2025-49113

https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-vulnerability-detection

https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-mitigation-script

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-49113

https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10

https://github.com/roundcube/roundcubemail/releases/tag/1.6.11

https://github.com/roundcube/roundcubemail/releases/tag/1.5.10

https://github.com/roundcube/roundcubemail/pull/9865

https://github.com/roundcube/roundcubemail/commit/c50a07d88ca38f018a0f4a0b008e9a1deb32637e

https://github.com/roundcube/roundcubemail/commit/7408f31379666124a39f9cb1018f62bc5e2dc695

https://github.com/roundcube/roundcubemail/commit/0376f69e958a8fef7f6f09e352c541b4e7729c4d

Details

Source: Mitre, NVD

Published: 2025-06-02

Updated: 2026-02-23

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.98897

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability of Interest