vulns.coMCP

← CVE intelligence

CVE-2025-49113 - RoundCube Webmail Deserialization of Untrusted Data Vulnerability

RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.

Severity
critical
Product
Roundcube Webmail
Published
2026-02-20
EPSS
0.989
CISA KEV
Known exploited
Ransomware
Known campaign use

References and validation

Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.