CVE-2025-49113

CRITICAL KEV NUCLEI LAB

Roundcube Webmail < 1.5.10 - Insecure Deserialization

Title source: rule

Description

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

Exploits (30)

exploitdb WORKING POC
by Maksim Rogov · webappsmultiple
https://www.exploit-db.com/exploits/52324
nomisec WORKING POC 96 stars
by fearsoff-org · poc
https://github.com/fearsoff-org/CVE-2025-49113
nomisec WORKING POC 90 stars
by hakaioffsec · remote-auth
https://github.com/hakaioffsec/CVE-2025-49113-exploit
github WRITEUP 7 stars
by cybersecplayground · poc
https://github.com/cybersecplayground/PoC-and-CVE-Reports/tree/main/2025/CVE-2025-49113.md
nomisec WORKING POC 7 stars
by 00xCanelo · remote-auth
https://github.com/00xCanelo/CVE-2025-49113
nomisec WORKING POC 6 stars
by BiiTts · remote-auth
https://github.com/BiiTts/Roundcube-CVE-2025-49113
nomisec SCANNER 5 stars
by rxerium · poc
https://github.com/rxerium/CVE-2025-49113
nomisec WORKING POC 3 stars
by Zwique · remote-auth
https://github.com/Zwique/CVE-2025-49113
nomisec WORKING POC 3 stars
by rasool13x · remote-auth
https://github.com/rasool13x/exploit-CVE-2025-49113
nomisec SCANNER 3 stars
by Ademking · poc
https://github.com/Ademking/CVE-2025-49113-nuclei-template
github SCANNER 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-49113
nomisec WORKING POC 2 stars
by SyFi · remote-auth
https://github.com/SyFi/CVE-2025-49113
nomisec WORKING POC 1 stars
by l4f2s4 · remote-auth
https://github.com/l4f2s4/CVE-2025-49113_exploit_cookies
nomisec WORKING POC 1 stars
by Joelp03 · remote-auth
https://github.com/Joelp03/CVE-2025-49113
nomisec WORKING POC 1 stars
by Yuri08loveElaina · remote-auth
https://github.com/Yuri08loveElaina/CVE-2025-49113
nomisec WORKING POC
by rippsec · remote
https://github.com/rippsec/CVE-2025-49113-Roundcube-RCE
nomisec WORKING POC
by mooder1 · poc
https://github.com/mooder1/CVE-2025-49113
nomisec WORKING POC
by Evillm · remote-auth
https://github.com/Evillm/CVE-2025-49113-PoC
nomisec WRITEUP
by ankitpandey383 · poc
https://github.com/ankitpandey383/roundcube-cve-2025-49113-lab
nomisec SUSPICIOUS
by Zuack55 · poc
https://github.com/Zuack55/Roundcube-1.6.10-Post-Auth-RCE-CVE-2025-49113-
nomisec STUB
by LeakForge · poc
https://github.com/LeakForge/CVE-2025-49113
nomisec WORKING POC
by AC8999 · remote-auth
https://github.com/AC8999/CVE-2025-49113
nomisec WORKING POC
by SteamPunk424 · remote-auth
https://github.com/SteamPunk424/CVE-2025-49113-Roundcube-RCE-PHP
nomisec WRITEUP
by CyberQuestor-infosec · poc
https://github.com/CyberQuestor-infosec/CVE-2025-49113-Roundcube_1.6.10
nomisec WORKING POC
by hackmelocal · poc
https://github.com/hackmelocal/CVE-2025-49113-Simulation
nomisec WORKING POC
by punitdarji · remote-auth
https://github.com/punitdarji/roundcube-cve-2025-49113
nomisec WRITEUP
by 5kr1pt · poc
https://github.com/5kr1pt/Roundcube_CVE-2025-49113
vulncheck_xdb WORKING POC
remote-auth
https://github.com/lcfr-eth/exploits
metasploit WORKING POC EXCELLENT
by Maksim Rogov, Kirill Firsov · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/roundcube_auth_rce_cve_2025_49113.rb

Nuclei Templates (1)

Roundcube Webmail - Remote Code Execution
CRITICALVERIFIEDby rootxharsh,iamnoooob,pdresearch,Ademking
Shodan: http.component:"roundcube"
FOFA: roundcube_sessid

Scores

CVSS v3 9.9
EPSS 0.9042
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull roundcube/roundcubemail:1.6.10-apache
docker pull instrumentisto/dovecot:latest
+25 more repos

Details

CISA KEV 2026-02-20
VulnCheck KEV 2025-06-04
ENISA EUVD EUVD-2025-16605
CWE
CWE-502
Status published
Products (3)
debian/debian_linux 11.0
roundcube/roundcubemail 0 - 1.5.10Packagist
roundcube/webmail < 1.5.10
Published Jun 02, 2025
KEV Added Feb 20, 2026
Tracked Since Feb 18, 2026