Deserialization of Untrusted Data in Roundcube Webmail - CVE-2025-49113

 

Deserialization of Untrusted Data in Roundcube Webmail - CVE-2025-49113

Published: June 1, 2025 / Updated: April 17, 2026


Vulnerability identifier: #VU110003
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-49113
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to insecure input validation when processing serialized data. A remote authenticated user can pass specially crafted data to the application and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Roundcube Webmail
Debian Linux
Arch Linux
Fedora
Ubuntu
roundcube (Ubuntu package)
roundcubemail
roundcube (Debian package)

How to mitigate CVE-2025-49113

Install updates from vendor's website.

Roundcube Webmail - addressed in versions 1.5.10, 1.6.11
roundcube (Ubuntu package) - addressed in versions 1.2~beta+dfsg.1-0ubuntu1+esm6, 1.3.6+dfsg.1-1ubuntu0.1~esm5, 1.4.3+dfsg.1-1ubuntu0.1~esm5, 1.5.0+dfsg.1-2ubuntu0.1~esm4, 1.6.6+dfsg-2ubuntu0.1, 1.6.8+dfsg-2ubuntu0.1, 1.6.10+dfsg-1ubuntu0.1
roundcubemail - addressed in versions 1.5.10-1.el9, 1.6.11-1.fc41, 1.6.11-1.fc42
roundcube (Debian package) - update to 1.6.5+dfsg-1+deb12u5
roundcubemail - update to 1.6.11-1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins