SVG Image Handling Vulnerability in Roundcube Webmail
CVE-2026-75003
5.8MEDIUM
What is CVE-2026-75003?
An issue in Roundcube Webmail versions prior to 1.6.18 and in the 1.7.x series before 1.7.3 allows an unclosed url() in a FuncIRI attribute of an SVG image. This oversight can bypass the protection mechanisms for remote image loading, which may lead to unauthorized information disclosure or privilege escalation within the application. It is important for users and administrators to update their installations to the latest versions to mitigate potential risks.
Affected Version(s)
Webmail 1.6.0 < 1.6.18
Webmail 1.7.0 < 1.7.3
