Deserialization of Untrusted Data in Roundcube Webmail - CVE-2025-49113
Published: June 1, 2025 / Updated: April 17, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote authenticated user can pass specially crafted data to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Debian Linux
Arch Linux
Fedora
Ubuntu
roundcube (Ubuntu package)
roundcubemail
roundcube (Debian package)
How to mitigate CVE-2025-49113
roundcube (Ubuntu package) - addressed in versions 1.2~beta+dfsg.1-0ubuntu1+esm6, 1.3.6+dfsg.1-1ubuntu0.1~esm5, 1.4.3+dfsg.1-1ubuntu0.1~esm5, 1.5.0+dfsg.1-2ubuntu0.1~esm4, 1.6.6+dfsg-2ubuntu0.1, 1.6.8+dfsg-2ubuntu0.1, 1.6.10+dfsg-1ubuntu0.1
roundcubemail - addressed in versions 1.5.10-1.el9, 1.6.11-1.fc41, 1.6.11-1.fc42
roundcube (Debian package) - update to 1.6.5+dfsg-1+deb12u5
roundcubemail - update to 1.6.11-1
Links to Public Exploits and PoC-codes
- Exploit #12602 - CVE-2025-49113-Roundcube-RCE (CVE-2025-49113 – Roundcube ≤1.6.10 post-auth RCE via PHP object deserialization (HackTheBox CTF)) (April 17, 2026)
- Exploit #11904 - CVE-2025-49113 (August 30, 2025)
- Exploit #11872 - CVE-2025-49113-Roundcube-RCE-PHP (This is a rewritten exploit to work with php) (August 22, 2025)
- Exploit #11866 - CVE-2025-49113 (August 22, 2025)
- Exploit #11794 - CVE-2025-49113 (July 18, 2025)
- Exploit #11729 - CVE-2025-49113-Scanner (June 27, 2025)
- Exploit #11694 - CVE-2025-49113 (June 20, 2025)
- Exploit #11673 - roundcube-cve-2025-49113 (June 20, 2025)
- Exploit #11667 - Roundcube_CVE-2025-49113 (June 20, 2025)
- Exploit #11633 - Roundcube-CVE-2025-49113 (June 13, 2025)
- Exploit #11557 - Roundcube ≤ 1.6.10 Post-Auth RCE via PHP Object Deserialization (June 11, 2025)
- Exploit #11484 - CVE-2025-49113 (June 6, 2025)
- Exploit #11482 - CVE-2025-49113 (June 6, 2025)
- Exploit #11476 - CVE-2025-49113-exploit (June 6, 2025)
- Exploit #11474 - exploit-CVE-2025-49113 (June 6, 2025)