Vulnerability record · CVE-2020-12641 · published 4 May 2020
CVE-2020-12641: Roundcube Webmail OS command injection via image conversion path settings
Roundcube · Webmail
Roundcube Webmail before 1.4.4 passes the im_convert_path and im_identify_path configuration settings to a shell without sanitization in rcube_image.php, allowing shell metacharacters to be injected. An attacker who can influence those settings can execute arbitrary OS commands on the mail server. The flaw is rated critical and is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, active inclusion in CISA KEV, very high EPSS probability, and public exploit code make this an urgent patch-first issue.
What it is
Roundcube Webmail before 1.4.4 passes the im_convert_path and im_identify_path configuration settings to a shell without sanitization in rcube_image.php, allowing shell metacharacters to be injected. An attacker who can influence those settings can execute arbitrary OS commands on the mail server. The flaw is rated critical and is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
Successful exploitation gives the attacker arbitrary command execution with the privileges of the web server process, enabling full compromise of the Roundcube host and any data it can reach. This can lead to mail data theft, lateral movement, and persistent access.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges or user interaction required per the CVSS vector, but exploitation depends on the ability to set or influence the im_convert_path or im_identify_path configuration values. In practice this means an attacker needs a path to modify those settings, such as a separate configuration flaw or administrative access, which the record does not detail.
Exploitation
CVE-2020-12641 is in CISA's KEV catalog with a due date of 2023-07-13, and EPSS shows a 30-day probability of 0.84336 (99.685th percentile). A public exploit reference is listed, and no ransomware campaign use is documented.
What to do
- Upgrade Roundcube Webmail to 1.4.4 or later (or the corresponding fixed 1.3.11 / 1.2.10 releases) immediately.
- If immediate upgrade is not possible, restrict access to Roundcube administration and configuration interfaces to trusted networks and accounts.
- Audit im_convert_path and im_identify_path settings for unexpected or attacker-controlled values and reset them to trusted binaries.
- Apply vendor patches for openSUSE backports and Leap packages where Roundcube is bundled.
- Monitor for unexpected child processes spawned by the web server user, especially ImageMagick-related binaries.
Detection
- Search web server and Roundcube logs for requests to rcube_image.php with unusual parameters or shell metacharacters.
- Monitor process creation events where the web server user spawns shells or unexpected commands (e.g., sh, bash, convert, identify).
- Alert on changes to Roundcube configuration files, particularly im_convert_path and im_identify_path.
- Correlate outbound network connections from the Roundcube host with process execution by the web server account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-12641 to the Known Exploited Vulnerabilities catalog on 22 June 2023 as "Roundcube Webmail Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 July 2023.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-12641 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-12641), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.