GHSA-8jr8-v43g-5c57

Suggest an improvement
Source
https://github.com/advisories/GHSA-8jr8-v43g-5c57
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-8jr8-v43g-5c57/GHSA-8jr8-v43g-5c57.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8jr8-v43g-5c57
Aliases
Published
2026-04-03T06:31:32Z
Modified
2026-04-04T07:11:22Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Roundcube Webmail: Unsanitized IMAP SEARCH command arguments
Details

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

Database specific
{
    "cwe_ids":  [
        "CWE-88"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-04T06:50:35Z",
    "nvd_published_at":  "2026-04-03T05:16:21Z",
    "severity":  "LOW"
}
References

Affected packages

Packagist / roundcube/roundcubemail

Package

Name
roundcube/roundcubemail
Purl
pkg:composer/roundcube/roundcubemail

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.7-beta
Fixed
1.7-rc5

Affected versions

1.*
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-8jr8-v43g-5c57/GHSA-8jr8-v43g-5c57.json"