CVE-2025-49113: RoundCube Webmail Deserialization of Untrusted Data Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2026-02-20. EPSS: 99% chance of exploitation in the next 30 days.

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Roundcube Webmail: before 1.5.10 (fixed in 1.5.10); from 1.6.0, before 1.6.11 (fixed in 1.6.11)

Published 2025-06-02. Last modified 2026-06-17.