Roundcube Webmail before 1.5.13 and 1.6.x before 1.6.13 contains a bypass of the “Block remote images” privacy feature: when remote images are blocked, SVG content using the SVG filter primitive element feImage is not blocked as expected. This allows remote content to be fetched despite the user/instance setting intended to prevent remote image loading.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository purpose: an email-delivered exploit toolkit for CVE-2026-25916 (Roundcube Webmail DOM-based XSS in SVG href/xlink:href handling) affecting Roundcube < 1.6.9. Structure: - README.md: vulnerability description, affected/fixed versions, example malicious SVG snippets, and example CLI usage showing SMTP parameters and a callback URL for data collection. - exploit_cve_2026_25732.py (main code; filename mismatches CVE but header/logic targets CVE-2026-25916): Python 3 script that logs into an SMTP server and sends a crafted email to one or many recipients. Exploit capabilities (from code and README): - Payload generation with basic obfuscation (string-splitting and comment noise) and multiple attack modes: - recon: collects URL, cookies, user agent, referrer, timestamp, and a generated sessionId; exfiltrates via an Image beacon to attacker callback. - session_steal: uses SVG <use href="javascript:..."> to execute JS and POST JSON (cookies, attempted CSRF token via input[name="_token"], URL, victim email, CVE tag) to callback. - keylogger: registers keydown listener and periodically exfiltrates keystrokes to callback. - action_hijack: (partially truncated in provided content) indicates use of fetch() to Roundcube internal endpoints like /?_task=mail&_action=compose to perform authenticated actions (e.g., sending email) as the victim. - Email delivery features: - Uses smtplib with TLS/SSL (ssl module) to authenticate and send MIME multipart email content. - CLI-driven operation (argparse) with options implied by README and main(): SMTP server/port/credentials, recipient, subject/from-name, callback URL, attack type, and a list/mass mode with delay. Notable observables: - Network: attacker-supplied SMTP server:port for sending; attacker-supplied callback URL for exfiltration; hardcoded example SMTP endpoint smtp.gmail.com:587 in README. - Target-side endpoints: Roundcube internal paths /?_task=mail&_action=send and /?_task=mail&_action=compose referenced in payloads for in-session actions. Overall: This is an operational exploit (not just detection) that weaponizes a DOM XSS in Roundcube’s SVG attribute sanitization by delivering malicious HTML/SVG via email, aiming at session theft/data exfiltration and potential account actions when the victim views the message in the Roundcube web UI.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.