Roundcube Webmail has released urgent security updates to address two critical vulnerabilities affecting versions 1.6 and 1.5 LTS. The first flaw is a Cross-Site Scripting (XSS) vulnerability in the SVG handling mechanism, which allows attackers to inject and execute arbitrary JavaScript code via the animate tag, potentially leading to the theft of session tokens, credentials, and sensitive email data. The second vulnerability is an information disclosure issue in the HTML style sanitizer, enabling attackers to bypass sanitization filters and access confidential information through specially crafted HTML content. Both vulnerabilities were reported by independent security researchers and pose significant risks to user privacy and data security.
Roundcube has released patched versions 1.6.12 and 1.5.12 to mitigate these threats and strongly recommends immediate updates for all affected installations. System administrators are urged to verify their current Roundcube version and apply the updates without delay, as exploitation in the wild is possible. The security community highlights the importance of prompt patching to prevent unauthorized access and information leakage in webmail environments.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Roundcube published security updates for supported branches to fix the SVG XSS and CSS sanitizer flaws. Administrators were advised to upgrade immediately because the vulnerabilities posed a high risk and may have been exploitable in the wild.
Two security flaws affecting Roundcube Webmail were disclosed: an XSS issue in SVG handling and an information disclosure issue in the HTML/CSS style sanitizer. The bugs could allow malicious script execution, theft of session data or credentials, and exposure of sensitive email information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.