CVE-2026-25916 describes a vulnerability in Roundcube Webmail versions prior to 1.5.13 and 1.6.13. When the "Block remote images" feature is enabled, it fails to block SVG feImage elements, potentially allowing for information disclosure. This is a medium-severity vulnerability (CVSS 4.3) with a low potential impact (C:L) and requires user interaction (UI:R) for exploitation. An attacker would need to craft a malicious email containing the SVG feImage element, which the user would then need to open. There is no evidence of active exploitation, nor are there publicly available exploit modules like Metasploit or Nuclei. Despite this, the vulnerability has garnered some community discussion and media coverage, primarily through security updates from openSUSE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 1.5.13CPE match | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
>= 1.6.0, < 1.6.13CPE match | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.