A fully functional proof-of-concept exploit for CVE-2025-49113
CVE-2025-49113 is an The vulnerability is the result of a logic flaw in the application's session parser, which allows insecure deserialization of PHP objects. Authenticated users can exploit this issue to execute arbitrary commands on the server.
An attacker with valid credentials (even low-privileged user accounts) can exploit this flaw to:
- Execute arbitrary system commands.
- Establish reverse shells or deploy persistence.
- Move laterally within the internal network if Roundcube is self-hosted.
- Type: Insecure Deserialization → Remote Code Execution
- Component: PHP backend (mail processing or plugin loading logic)
- Conditions: Authenticated session (cookie or login), crafted serialized payload
- Exploit Primitive: PHP
unserialize()with attacker-controlled input and loaded gadgets
- 1.5.x: All versions from
1.5.0to1.5.9 - 1.6.x: All versions from
1.6.0to1.6.10
Versions prior to 1.5.0 have not been tested, but are potentially vulnerable if backported plugins or features are present.
- Python ≥ 3.7
- PHP ≥ 7.4 (used for local payload crafting)
- Python libraries listed in
requirements.txt
Clone the repository and install the required dependencies:
git clone https://github.com/BiiTts/Roundcube-CVE-2025-49113.git
cd roundcube-rce-CVE-2025-49113
pip install -r requirements.txtpython3 roundcube_exploit.py http://roundcube.local/ username password "cmd"https://fearsoff.org/research/roundcube