Cross-site scripting in Roundcube Webmail - CVE-2025-68461
Published: December 15, 2025 / Updated: February 23, 2026
Vulnerability identifier: #VU119952
CSH Severity: High
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2025-68461
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data when handling SVG’s animate tag. A remote user can upload a specially crafted SVG image and perform XSS attack.
Affected software
Roundcube Webmail
Debian Linux
Ubuntu
roundcube (Ubuntu package)
roundcube (Debian package)
Debian Linux
Ubuntu
roundcube (Ubuntu package)
roundcube (Debian package)
How to mitigate CVE-2025-68461
Install updates from vendor's website.
Roundcube Webmail - addressed in versions 1.5.12, 1.6.12
roundcube (Ubuntu package) - addressed in versions 1.3.6+dfsg.1-1ubuntu0.1~esm6, 1.4.3+dfsg.1-1ubuntu0.1~esm6, 1.5.0+dfsg.1-2ubuntu0.1~esm5, 1.6.6+dfsg-2ubuntu0.1+esm2, 1.6.11+dfsg-1ubuntu0.26.04.1~esm1
roundcube (Debian package) - addressed in versions 1.6.5+dfsg-1+deb12u6, 1.6.12+dfsg-0+deb13u1
roundcube (Ubuntu package) - addressed in versions 1.3.6+dfsg.1-1ubuntu0.1~esm6, 1.4.3+dfsg.1-1ubuntu0.1~esm6, 1.5.0+dfsg.1-2ubuntu0.1~esm5, 1.6.6+dfsg-2ubuntu0.1+esm2, 1.6.11+dfsg-1ubuntu0.26.04.1~esm1
roundcube (Debian package) - addressed in versions 1.6.5+dfsg-1+deb12u6, 1.6.12+dfsg-0+deb13u1