Input validation error in Roundcube Webmail - #VU141378

 

Input validation error in Roundcube Webmail - #VU141378

Published: August 9, 2026


Vulnerability identifier: #VU141378
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass HTML and CSS sanitization.

The vulnerability exists due to improper input validation in the HTML/CSS sanitizer when processing the SVG animate by attribute. A remote attacker can supply crafted SVG content to bypass HTML and CSS sanitization.

User interaction is required to render the crafted content.


Affected software

Roundcube Webmail

Remediation

Install security update from vendor's website.

Roundcube Webmail - addressed in versions 1.6.18, 1.7.3

External References

Related Security Bulletins