Input validation error in Roundcube Webmail - #VU141378
Published: August 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass HTML and CSS sanitization.
The vulnerability exists due to improper input validation in the HTML/CSS sanitizer when processing the SVG animate by attribute. A remote attacker can supply crafted SVG content to bypass HTML and CSS sanitization.
User interaction is required to render the crafted content.