CVE-2025-49113 – Remote Code Execution Vulnerability in Roundcube Webmail

ISGroup Cybersecurity

A critical Remote Code Execution (RCE) vulnerability, identified as CVE‑2025‑49113, has been discovered in Roundcube Webmail. The flaw affects versions prior to 1.5.10 and 1.6.x versions prior to 1.6.11. An authenticated user can exploit improper validation of the _from parameter in the program/actions/settings/upload.php file to execute arbitrary code on the server. A public proof-of-concept exists, and active attacks are currently underway. Approximately 84,000 instances exposed on the internet are vulnerable.

ProductRoundcube Webmail
Date2025-07-02 10:12:50
Information
  • Fix Available
  • Active Exploitation

Technical Summary

The flaw stems from insecure deserialization by Roundcube of user-controlled data sent via the _from parameter — an attacker with valid credentials (e.g., a low-privileged user) can send a specially crafted POST request to upload.php, injecting a malicious PHP object that leads to arbitrary code execution on the server.

• Exploit impact: attackers can compromise confidentiality, integrity, and availability, potentially moving laterally to other systems. • Shadowserver scans have identified over 84,000 vulnerable hosts across major cloud providers and hosting environments.

Recommendations

1- Apply the patch immediately: update Roundcube to version 1.5.10 or 1.6.11. 2- Change passwords: update the passwords of all Roundcube users to prevent unauthorized access. 3- Apply the principle of least privilege: ensure the web server user (e.g., www-data or nobody) has minimal permissions and avoid setting broad write permissions (e.g., 0777) on sensitive directories. 4- Apply input validation: implement strict sanitization on the _from parameter (e.g., allow only simple strings that match email addresses or internal paths). 5- Monitor logs: regularly check server logs (e.g., /var/log/litespeed/error.log) for suspicious activity. 6- Disable unnecessary features: if possible, disable the settings upload functionality if it is not required.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert