Description
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.
Published: 2026-08-17
Score: 5.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Roundcube Webmail versions prior to 1.6.18 and 1.7.x before 1.7.3 suffer from improper sanitization of the SVG animate "by" attribute, which allows an attacker to craft an SVG that bypasses the remote image blocking filter. This flaw can lead to information disclosure or privilege escalation if a user opens the crafted content. The CVSS score of 5.8 indicates a moderate severity.

Affected Systems

The affected product is Roundcube Webmail. Users running any version before 1.6.18 or before 1.7.3 are susceptible. The exact models are Roundcube versions 1.6.x prior to 1.6.18 and 1.7.x prior to 1.7.3.

Risk and Exploitability

With a CVSS score of 5.8 and no EPSS data, the likelihood of exploitation is currently unknown, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, where an attacker sends a malicious SVG attachment or URL to a victim. Once the victim views the content, the remote image blocking bypass can reveal sensitive data or elevate privileges.

Generated by OpenCVE AI on August 17, 2026 at 14:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Roundcube to version 1.6.18 or later including 1.7.3 or newer
  • Disable external image loading in the webmail settings if the workflow permits
  • Regularly audit SVG handling code for proper sanitization of all attributes

Generated by OpenCVE AI on August 17, 2026 at 14:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Title SVG Animate Attribute Sanitization Leading to Remote Image Blocking Bypass in Roundcube Webmail

Mon, 17 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.
First Time appeared Roundcube
Roundcube webmail
Weaknesses CWE-669
CPEs cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
Vendors & Products Roundcube
Roundcube webmail
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Roundcube Webmail
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-17T14:59:34.936Z

Reserved: 2026-08-17T12:45:56.473Z

Link: CVE-2026-75000

cve-icon Vulnrichment

Updated: 2026-08-17T14:35:42.597Z

cve-icon NVD

Status : Received

Published: 2026-08-17T13:16:54.580

Modified: 2026-08-17T15:16:59.447

Link: CVE-2026-75000

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T15:00:08Z

Weaknesses
  • CWE-669

    Incorrect Resource Transfer Between Spheres