Impact
The vulnerability originates from insufficient CSS sanitization when Roundcube Webmail renders HTML e‑mail messages. Because the application permits external CSS links within email content, an attacker can craft a message that references internal network hosts or local file URLs. When a user opens or pre‑renders such an email, Roundcube will retrieve the linked resource, potentially leaking internal services or configuration data. The weakness is classified as CWE‑918.
Affected Systems
The affected installations are Roundcube Webmail versions earlier than 1.6.17 and releases in the 1.7.x series earlier than 1.7.2. Any deployment that uses the default email rendering settings without additional CSS sanitization controls falls within this risk envelope.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, but the EPSS score of < 1% suggests exploitation is unlikely but still technically feasible. The vulnerability is not listed in the CISA KEV catalog. Attackers would normally deliver a crafted e‑mail containing a malicious CSS link; successful exploitation requires the victim to open or automatically render the e‑mail, which is common with automated mail readers, making the threat surface moderate.
OpenCVE Enrichment
Debian DLA
Debian DSA