Vulnerability record · CVE-2018-19206 · published 12 November 2018
CVE-2018-19206: Roundcube webmail XSS via crafted SVG in HTML attachment
Roundcube · Webmail
Roundcube before 1.3.8 fails to properly sanitize HTML attachments, allowing cross-site scripting through crafted use of <svg><style> and an onload attribute in a BODY element. Because the flaw lives in the mail display path, a malicious message can execute script in the webmail origin when the victim views the attachment.
Description
steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityHigh EPSS (99th percentile) and a remotely reachable, low-complexity XSS in a widely deployed webmail client outweigh the medium CVSS base score.
What it is
Roundcube before 1.3.8 fails to properly sanitize HTML attachments, allowing cross-site scripting through crafted use of <svg><style> and an onload attribute in a BODY element. Because the flaw lives in the mail display path, a malicious message can execute script in the webmail origin when the victim views the attachment.
Impact
An attacker can run script in the victim's webmail session, potentially reading mail, stealing session data, or performing actions as the logged-in user. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached remotely over the network by sending a crafted HTML attachment; no authentication is needed to deliver the message, but the victim must open or view the attachment (UI:R).
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at 0.55852 (99th percentile), suggesting elevated likelihood of exploitation activity.
What to do
- Upgrade Roundcube to 1.3.8 or later, or apply the Debian DSA-4344 update for packaged installs.
- Disable or restrict rendering of HTML attachments in webmail until patched.
- Deploy a content security policy that blocks inline script in the webmail origin.
- Filter or strip SVG and style content from inbound HTML attachments at the mail gateway.
Detection
- Search webmail and proxy logs for HTML attachments containing <svg><style> or onload attributes in BODY elements.
- Alert on script execution or unexpected outbound requests originating from the webmail origin.
- Monitor for anomalous session activity or mail access patterns following attachment views.
- Review mail gateway rules for SVG-bearing attachments that bypass sanitization.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/roundcube/roundcubemail/releases/tag/1.3.8 | Release Notes |
| https://roundcube.net/news/2018/10/26/update-1.3.8-released | Release NotesVendor Advisory |
| https://www.debian.org/security/2018/dsa-4344 | Third Party Advisory |
| https://github.com/roundcube/roundcubemail/releases/tag/1.3.8 | Release Notes |
| https://roundcube.net/news/2018/10/26/update-1.3.8-released | Release NotesVendor Advisory |
| https://www.debian.org/security/2018/dsa-4344 | Third Party Advisory |
Track CVE-2018-19206 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-19206), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.