logo

Roundcube Webmail Vulnerability Let Attackers Track Email Opens

ID: b9641bc9-b312-57fc-ae99-6b642e7b79c2

STIX ID: report--b9641bc9-b312-57fc-ae99-6b642e7b79c2

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2026-02-09

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Roundcube Webmail versions prior to 1.5.13 and 1.6.x prior to 1.6.13 contain a privacy-bypass vulnerability: the HTML sanitizer failed to treat the SVG filter primitive <feImage> as an image attribute, allowing remote-image fetches to bypass "Block remote images" settings; attackers can embed a 1×1 SVG to confirm addresses, log recipient IPs, and fingerprint devices. Maintainers released fixes in versions 1.5.13 and 1.6.13 and administrators are urged to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.