1

Topic: CVE-2025-49113 & CVE-2025-68461 RoundCube?

Hi Zhang,
Do you plan to release a patch for these CVEs?

CVE-2025-49113 RoundCube Webmail Deserialization of Untrusted Data Vulnerability
CVE-2025-68461 RoundCube Webmail Cross-site Scripting Vulnerability

Thanks,
Ray

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2

Re: CVE-2025-49113 & CVE-2025-68461 RoundCube?

https://github.com/iredmail/iRedMail/co … e51e8c9b97

Both CVE were patched in 1.6.13

RoundCube is kind of standalone and not directly part of iRedMail, it i just a 3rd party integration, and noone is foced to use it (optional during installation)

Everyone is required to pull relevant securty updates on their own

3

Re: CVE-2025-49113 & CVE-2025-68461 RoundCube?

Please upgrade Roundcube to latest 1.6.13.
We're preparing new iRedMail release with this patched version.