CVE-2020-13965
KEV PoC massXSS via Malicious XML Attachment in Roundcube Webmail
CISA: Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5 is vulnerable to cross-site scripting via malicious XML attachments, because text/xml is among the MIME types the client renders in the attachment preview, allowing embedded markup or script to execute in the victim's browser. An attacker triggers the flaw by emailing a crafted XML attachment and persuading a user to preview it. Successful exploitation lets the attacker run arbitrary JavaScript in the victim's webmail session, potentially hijacking the session, reading or manipulating mail, or acting as the user. Any Roundcube deployment running an affected version is exposed, including the Roundcube packages shipped in Debian and Fedora, though the share of installs still unpatched in 2024 is not documented in the available data. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-06-26, confirming exploitation in the wild, and a public proof-of-concept is available with EPSS at roughly 77% probability of exploitation within 30 days.
What to do: Upgrade Roundcube to 1.3.12 or later on the 1.3 branch, or 1.4.5 or later on the 1.4 branch. If immediate patching is not possible, apply vendor mitigations — such as removing text/xml from the MIME types permitted for attachment preview — or discontinue use of the product per CISA's required action. Audit mail servers and hosting panels for Roundcube versions and monitor for suspicious activity around XML attachment previews.
| Roundcube Webmail | before 1.3.12 and 1.4.x before 1.4.5 |
| Debian Linux (Roundcube package) | packages shipping Roundcube before 1.3.12 or 1.4.x before 1.4.5 (exact affected Debian releases not specified in source data) |
| fedoraproject Fedora (Roundcube package) | packages shipping Roundcube before 1.3.12 or 1.4.x before 1.4.5 (exact affected Fedora releases not specified in source data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
- Affected
- Roundcube Webmail
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- roundcubedebianfedoraproject
- Products
- webmail, debian linux, fedora
- Weakness
- CWE-79, CWE-80
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N