Impact
This vulnerability arises from incomplete sanitization of Cascading Style Sheets in HTML messages processed by Roundcube Webmail. When an email contains a link to an external stylesheet that points to a host on the local network, the webmail client can inadvertently request that file, exposing internal resources. The flaw is categorized as CWE‑918 (Improper Verification of Escape or Input Validation in Style Sheets).
Affected Systems
The affected vendor is Roundcube, for the Webmail product. Versions prior to 1.6.18 and 1.7.x before 1.7.3 are impacted. All installations that have not upgraded to these releases remain vulnerable.
Risk and Exploitability
The CVSS score of 5.8 reflects a medium severity assessment with potential for SSRF and local information disclosure. EPSS data is not available and the vulnerability is currently not listed in CISA's KEV catalog, suggesting limited public exploitation at this time. The most likely attack vector is remote: an adversary can send a crafted email that includes an external stylesheet link targeting an internal host, causing the victim's webmail session to trigger a request that could reveal internal services or data. Prompt application of the available patch is the recommended remediation.
OpenCVE Enrichment