Known vulnerability record

CVE-2025-49113

RoundCube Webmail Deserialization of Untrusted Data Vulnerability

Stable IDcve:CVE-2025-49113Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

RoundCube Webmail Deserialization of Untrusted Data Vulnerability

RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.

Keep the signals separate

CVSS severitycriticalScore 9.9 · source mitre
EPSS probability97.7%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-02-20
Ransomware useunknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2025-06-02
CVE modified
2026-02-21
KEV date added
2026-02-20
Dataset fetched
2026-08-21T03:55:10.107Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.