CVE-2024-42008 is a cross-site scripting vulnerability in Roundcube Webmail affecting versions through 1.5.7 and 1.6.x through 1.6.7. The flaw is located in the rcmail_action_mail_get->run() code path and can be triggered through a malicious email attachment served with a dangerous Content-Type header. When a victim interacts with the crafted attachment in the Roundcube web interface, attacker-controlled script can execute in the context of the victim’s authenticated webmail session. This enables browser-side compromise of the user’s mailbox session and access to data and actions available to that user.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept exploit for CVE-2024-42008, a Cross-Site Scripting (XSS) vulnerability in RoundCube Webmail (<=1.5.7 and 1.6.x <=1.6.7). The exploit consists of a Python script (script.py) and a detailed README.md. The script automates the process of injecting a malicious HTML/JavaScript payload into the RoundCube contact form. When a victim opens the malicious email, the payload uses CSS animation and the onanimationstart event to execute JavaScript in the victim's browser, which fetches emails from the INBOX and exfiltrates them to the attacker's server. The script also starts a local HTTP server to receive and log the stolen data. The exploit is configurable (attacker IP, port, recipient, target URL, proxy) and supports debug and continuous modes. The README provides comprehensive technical details, usage instructions, and ethical guidelines. The main attack vector is browser-based XSS, with network exfiltration of data to the attacker's server. The repository is structured for educational and penetration testing use, not for weaponization.
This repository contains a proof-of-concept exploit for CVE-2024-42008 and CVE-2024-42009, targeting Roundcube Webmail version 1.6.7. The exploit consists of a Python script (script.py) and a JavaScript payload (exploit.js). The Python script crafts a malicious email containing a base64-encoded JavaScript payload and sends it to a victim's email address via the Roundcube contact form. When the victim opens the email in Roundcube, the JavaScript executes in their browser, reads the content of up to 10 emails from their inbox, and exfiltrates the data via POST requests to an attacker-controlled server (the IP must be set by the attacker in the script). The README provides context and setup instructions, including the need for a custom HTTP server to receive POST requests. The exploit leverages a browser-based attack vector (XSS) and targets specific HTTP endpoints on the Roundcube instance and the attacker's server.
This repository is a proof-of-concept (PoC) exploit for two vulnerabilities in Roundcube Webmail: CVE-2024-42008 (XSS via XML attachment) and CVE-2024-42010 (CSS injection for exfiltration). The repository contains two files: a README.md with detailed attack instructions and a Node.js script (roundcube-css-exploit.js) that acts as a malicious server to serve CSS and collect exfiltrated data. The exploit chain involves sending a crafted email with a malicious XML attachment and a CSS import referencing the attacker's server. When a victim opens the email, the CSS is loaded from the attacker's domain, which then exfiltrates the UID of the malicious attachment. The Node.js script implements endpoints (/start, /leak, /next, /end) to facilitate the exfiltration process. The exploit targets Roundcube Webmail and requires the attacker to host a server with a valid SSL certificate. The code is a functional PoC and demonstrates the attack chain but does not include weaponized payloads beyond exfiltration and XSS demonstration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity Roundcube cross-site scripting vulnerability in rcmail_action_mail_get->run() that can be triggered via a malicious Content-Type header in an email attachment; exploitation requires victim interaction with the attachment.
Vulnérabilité critique de type XSS (injection de code indirecte à distance) dans Roundcube Webmail pouvant mener à l’accès au contenu des courriels et potentiellement à l’envoi de courriels en usurpant la victime; nécessite une action utilisateur supplémentaire au-delà de l’ouverture du message.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.