CVE-2025-49113
KEVCRITICAL 9.9EPSS 99.0%
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.9 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - CVSS v3.1
- 9.9 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - EPSS
- 99.03% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2026-02-20
- Nuclei
- critical · CWE-502
- Published
- 2025-06-02
- Updated
- 2026-02-21
Proof-of-concept exploits (24)
- https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-mitigation-script
- https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-vulnerability-detection
- 00xCanelo/CVE-2025-491138★ · 2025-07-19
- 5kr1pt/Roundcube_CVE-2025-491130★ · 2025-06-17
- AC8999/CVE-2025-491130★ · 2025-08-29
- BiiTts/Roundcube-CVE-2025-491136★ · 2025-06-10
- CyberQuestor-infosec/CVE-2025-49113-Roundcube_1.6.100★ · 2025-08-18
- Joelp03/CVE-2025-491131★ · 2025-07-18
- LeakForge/CVE-2025-491130★ · 2025-08-30
- SteamPunk424/CVE-2025-49113-Roundcube-RCE-PHP1★ · 2025-08-19
- SyFi/CVE-2025-491132★ · 2025-06-06
- Zuack55/Roundcube-1.6.10-Post-Auth-RCE-CVE-2025-49113-0★ · 2025-09-10
- Zwique/CVE-2025-491135★ · 2025-08-25
- a-s-m-asadujjaman/exploitables0★ · 2026-06-12
- fearsoff-org/CVE-2025-49113109★ · 2025-06-06
- hackmelocal/CVE-2025-49113-Simulation0★ · 2025-07-24
- hakaioffsec/CVE-2025-49113-exploit93★ · 2025-06-06
- l4f2s4/CVE-2025-49113_exploit_cookies1★ · 2025-09-19
- lcfr-eth/exploits25★ · 2026-05-12
- punitdarji/roundcube-cve-2025-491130★ · 2025-06-22
- rasool13x/exploit-CVE-2025-491133★ · 2025-06-06
- rxerium/CVE-2025-491135★ · 2025-10-24
- Evillm/CVE-2025-49113-PoC
- mooder1/CVE-2025-49113