CRLF injection in Roundcube Webmail - #VU124138
Published: March 19, 2026 / Updated: March 19, 2026
Roundcube Webmail
Detailed vulnerability description
The vulnerability allows a remote user to perform IMAP command injection and bypass CSRF protections.
The vulnerability exists due to improper input validation in mail search functionality when handling search queries. A remote user can send a specially crafted search request containing malicious IMAP commands to execute arbitrary commands on the IMAP server and bypass CSRF restrictions.