Impact
The vulnerability originates from an absence of validation on responses received from the CSS proxy in Roundcube Webmail. Because the proxy can deliver arbitrary CSS content that is not checked, an attacker can supply crafted CSS that triggers MIME sniffing by the browser. This can lead to cross‑site scripting attacks where malicious code is executed in the victim's browser session or result in the disclosure of sensitive information. The weakness is a classic reflected input flaw that falls under CWE‑79, allowing an attacker to inject code that the client processes without proper sanitization.
Affected Systems
Affected installations are Roundcube Webmail versions prior to 1.6.18 and any 1.7.x release before 1.7.3. The issue is present in all builds of the Roundcube code base that lack the validation change introduced in the 1.6.18 and 1.7.3 releases. Users running those earlier releases should consult the vendor advisories for upgrade guidance.
Risk and Exploitability
The CVSS score indicates a high severity of 7.2. The EPSS value is not available, indicating that public data does not provide an exploitation probability estimate, but the lack of input validation makes exploitation technically straightforward for an attacker who can direct a victim to the vulnerable CSS proxy endpoint. Because the flaw propagates via client‑side code, an attacker may need to entice a user to visit a malicious site or a compromised mailbox; nevertheless, the knowledge of the flaw and the ability to supply arbitrary CSS makes the risk substantial. The vulnerability is not listed in CISA’s KEV catalog, implying no widely known exploitation has yet been observed, but the high CVSS and potential for XSS justify prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA