Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
jbz
jbz
@jbz@indieweb.social  ·  activity timestamp 2 days ago

⚠️ Roundcube Webmail <1.5.13 / <1.6.13 allows attackers to force remote image loads via SVG feImage

「 Roundcube’s rcube_washtml sanitizer blocked external resources on <img>, <image>, and <use>, but not on <feImage>. Its href went through the wrong code path and got allowed through. Attackers could track email opens even when “Block remote images” was on. Fixed in 1.5.13 and 1.6.13 」

https://nullcathedral.com/posts/2026-02-08-roundcube-svg-feimage-remote-image-bypass/

#roundcube #tracking

NULL CATHEDRAL

Roundcube Webmail <1.5.13 / <1.6.13 allows attackers to force remote image loads via SVG feImage

Roundcube's HTML sanitizer doesn't treat SVG feImage href as an image source. Attackers can bypass remote image blocking to track email opens.
  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.7 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct