GHSA-5hf6-crg4-fg59

Suggest an improvement
Source
https://github.com/advisories/GHSA-5hf6-crg4-fg59
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-5hf6-crg4-fg59/GHSA-5hf6-crg4-fg59.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5hf6-crg4-fg59
Aliases
Published
2026-04-03T06:31:32Z
Modified
2026-04-04T07:11:22Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Roundcube: Bypass of remote image blocking via crafted BODY background attribute
Details

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.

Database specific
{
    "cwe_ids":  [
        "CWE-669"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-04T06:55:40Z",
    "nvd_published_at":  "2026-04-03T05:16:22Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / roundcube/roundcubemail

Package

Name
roundcube/roundcubemail
Purl
pkg:composer/roundcube/roundcubemail

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.7-beta
Fixed
1.7-rc5

Affected versions

1.*
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-5hf6-crg4-fg59/GHSA-5hf6-crg4-fg59.json"