Cross-Site Scripting Vulnerability in Roundcube Webmail from Roundcube
CVE-2025-68461
Key Information:
Badges
What is CVE-2025-68461?
CVE-2025-68461 is a Cross-Site Scripting (XSS) vulnerability identified in Roundcube Webmail, which is an open-source webmail application used widely for email management. This vulnerability affects versions prior to 1.5.12 and 1.6 prior to 1.6.12, enabling an attacker to execute malicious scripts in the context of a user's session. The exploit leverages the animate tag within an SVG document, which can lead to unauthorized actions taken on behalf of the user, potentially compromising sensitive information and undermining the overall security of the webmail system. Organizations relying on Roundcube for their email communication may face significant repercussions, such as data breaches or potential unauthorized access to user accounts.
Potential impact of CVE-2025-68461
-
Data Compromise: Attackers exploiting this vulnerability can execute arbitrary scripts, which may lead to the theft of sensitive information, such as login credentials and personal data.
-
User Session Hijacking: By executing scripts in the context of a user session, adversaries could impersonate users, allowing them to perform unauthorized actions, thereby jeopardizing user trust and system integrity.
-
Propagation of Malware: The XSS vulnerability can be used to deliver malicious payloads to users, potentially resulting in the spread of malware or more sophisticated attacks across the network.
CISA has reported CVE-2025-68461
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2025-68461 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Webmail 0 < 1.5.12
Webmail 1.6.0 < 1.6.12
News Articles
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- π°
First article discovered by BleepingComputer
- πΎ
Exploit known to exist
- π¦
CISA Reported
- π
Vulnerability started trending
Vulnerability published
Vulnerability Reserved
