Cross-site scripting in Roundcube Webmail - #VU147187
Published: September 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script.
The vulnerability exists due to improper neutralization of input during web page generation in attachment URL handling when processing TNEF MIME tag input. A remote attacker can send an email containing a crafted TNEF MIME tag to execute arbitrary script.
No user interaction is required.