Cross-site scripting in Roundcube Webmail - CVE-2026-48848
Published: May 25, 2026 / Updated: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary style content.
The vulnerability exists due to improper input validation in the HTML sanitizer when processing SVG animate elements with attributeName="style". A remote attacker can supply specially crafted HTML or SVG content to inject arbitrary style content.
Affected software
Debian Linux
roundcube (Debian package)
How to mitigate CVE-2026-48848
roundcube (Debian package) - addressed in versions 1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1