A severe security flaw in Roundcube webmail software has been uncovered after remaining hidden for ten years. Tracked as CVE-2025-49113 with a near-maximum CVSS score of 9.9, this vulnerability could allow attackers to execute arbitrary code on affected systems.
The flaw is classified as a post-authenticated remote code execution vulnerability via PHP object deserialization. According to the National Vulnerability Database, “Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.”
All versions prior to and including 1.6.10 are affected. Users should immediately update to patched versions 1.6.11 or 1.5.10 LTS.
Kirill Firsov, founder and CEO of Dubai-based cybersecurity firm FearsOff, discovered and reported the vulnerability. The company plans to release technical details and a proof-of-concept soon, allowing users adequate time to apply patches.
Roundcube has previously been targeted by nation-state threat actors including APT28 and Winter Vivern. Last year, hackers exploited a different Roundcube vulnerability (CVE-2024-37383) in phishing campaigns to steal credentials. More recently, ESET reported that APT28 used cross-site scripting vulnerabilities in various webmail servers including Roundcube to harvest sensitive data from government and defense organizations in Eastern Europe.
