CVE-2025-68461
KEVmassCross-Site Scripting via SVG animate Tag in Roundcube Webmail
CISA: RoundCube Webmail Cross-site Scripting Vulnerability
Roundcube Webmail contains a cross-site scripting flaw (CWE-79) that arises when rendering SVG documents, because the SVG 'animate' element is not properly sanitized. An attacker can deliver a crafted SVG document, for example within an email, so that when the recipient views it in the Roundcube web interface, attacker-controlled script executes in the context of the victim's webmail session. Successful exploitation lets the attacker run arbitrary JavaScript in the victim's browser, enabling session hijacking, theft of cookies or credentials, and reading or manipulating the victim's mail and webmail settings. Any organization running Roundcube is potentially affected, including hosting providers, ISPs, universities, and enterprises, where it frequently serves as the default webmail client. CISA added the flaw to the KEV catalog on 2026-02-20, indicating confirmed in-the-wild exploitation, with a 26.8% EPSS probability of exploitation within 30 days (98th percentile); CVSS has not yet been scored and no public proof-of-concept is known.
What to do: Upgrade Roundcube to the patched release identified in the vendor's security advisory, and for cPanel-managed servers apply the cPanel-shipped Roundcube update; do not defer patching given active exploitation. Until patched, apply vendor-recommended mitigations and hunt mail and web access logs for emails containing SVG content followed by anomalous webmail session activity. Federal agencies must apply the mitigations per vendor instructions or follow BOD 22-01 guidance per the CISA KEV listing.
| Roundcube Webmail | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
- Affected
- Roundcube Webmail
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- roundcube
- Products
- webmail
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N