Roundcube CVE-2025-49113: Authenticated PHP Object Deserialization to RCE in Open-Source Webmail
Attribution. This is an original English rewrite based on the article “Critical Remote Code Execution (RCE) in Roundcube, CVE-2025-49113: Your Email is Not Safe!” by AirCorridor on Hackers Arise (published 25 July 2025). The technical analysis, walkthrough and screenshots are the original author’s work; this page paraphrases the prose in our own words, preserves every…
https://core-jmp.org/2026/05/roundcube-cve-2025-49113-authenticated-rce-php-deserialization/
Post #3401
4.6K

- 🔥 7
- 👍 3