Roundcube Flaws Let Attackers Execute Malicious Scripts
Roundcube, a widely used open-source webmail software, has released critical security updates to address two significant vulnerabilities in its 1.6 and 1.5 LTS (Long-Term Support) versions.
Roundcube, a widely used open-source webmail software, has released critical security updates to address two significant vulnerabilities in its 1.6 and 1.5 LTS (Long-Term Support) versions.
These vulnerabilities could allow attackers to execute malicious scripts or expose sensitive information, posing a risk to organizations and individuals using the platform for email communication.
The maintainers of Roundcube Webmail published the security fixes on Sat, Dec 13, 2025, urging administrators to update their installations immediately. The new release versions, 1.6.12 and 1.5.12, specifically address these issues to secure the email environment against potential exploitation.
The first and most concerning issue addressed in this update is a Cross-Site Scripting (XSS) vulnerability. This flaw was discovered in how the software handles SVG (Scalable Vector Graphics) images, specifically involving the animate tag.
The maintainers of Roundcube Webmail published the security fixes on Sat, Dec 13, 2025, urging administrators to update their installations immediately.
The second vulnerability is an Information Disclosure flaw located within the HTML style sanitizer. This component is responsible for cleaning up HTML emails to ensure they do not contain harmful code. However, a bypass in this sanitizer could allow an attacker to reveal data that should remain hidden.
The Roundcube team has strongly recommended that all productive installations running the 1.6.x and 1.5.x branches be updated immediately to the latest versions (1.6.12 and 1.5.12).
For administrators, the complete changelogs and download files are available on the official Roundcube GitHub release pages. Keeping webmail clients patched is essential, as they are often public-facing entry points into an organization's internal network. Failure to apply these patches could leave users vulnerable to targeted XSS attacks aimed at compromising email accounts and sensitive communications.
Based on reporting by GBHackers.
