https://seclists.org/oss-sec/2025/q2/191: Roundcube webmail: Post-Auth RCE via PHP Object Deserialization ported by firs0v
Published Jun 2, 2025
·Updated
Affected Software
1 affected component
Roundcube Roundcube
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX?
CVE-2025-XXXX has been classified with a high severity rating due to its potential for post-authentication remote code execution.
2
How do I fix CVE-2025-XXXX?
To fix CVE-2025-XXXX, update Roundcube to the latest versions 1.6.11 or 1.5.10, where the vulnerability has been addressed.
3
What is the impact of CVE-2025-XXXX on Roundcube?
CVE-2025-XXXX allows authenticated users to execute arbitrary code through PHP object deserialization attacks.
4
When was CVE-2025-XXXX published?
CVE-2025-XXXX was published on June 2, 2025, following the discovery of the vulnerability.
5
Which versions of Roundcube are affected by CVE-2025-XXXX?
Versions of Roundcube prior to 1.5.10 and 1.6.11 are affected by CVE-2025-XXXX.