Input validation error in Roundcube Webmail - #VU132217
Published: May 25, 2026
Roundcube Webmail
Detailed vulnerability description
The vulnerability allows a remote attacker to cause remote images to be loaded despite blocking restrictions.
The vulnerability exists due to improper input validation in remote image blocking logic when processing CSS var() constructs. A remote attacker can supply specially crafted content using CSS var() to cause remote images to be loaded despite blocking restrictions.