← Vulnerability feed

Vulnerability record · CVE-2020-12641 · published 4 May 2020

CVE-2020-12641: Roundcube Webmail OS command injection via image conversion path settings

Roundcube · Webmail

Roundcube Webmail before 1.4.4 passes the im_convert_path and im_identify_path configuration settings to a shell without sanitization in rcube_image.php, allowing shell metacharacters to be injected. An attacker who can influence those settings can execute arbitrary OS commands on the mail server. The flaw is rated critical and is listed in CISA's Known Exploited Vulnerabilities catalog.

9.8 CVSS 3.1 Critical CISA KEV since 22 Jun 2023 EPSS 84% · top 0.3% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 7.5
84%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
15References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, active inclusion in CISA KEV, very high EPSS probability, and public exploit code make this an urgent patch-first issue.

What it is

Roundcube Webmail before 1.4.4 passes the im_convert_path and im_identify_path configuration settings to a shell without sanitization in rcube_image.php, allowing shell metacharacters to be injected. An attacker who can influence those settings can execute arbitrary OS commands on the mail server. The flaw is rated critical and is listed in CISA's Known Exploited Vulnerabilities catalog.

Impact

Successful exploitation gives the attacker arbitrary command execution with the privileges of the web server process, enabling full compromise of the Roundcube host and any data it can reach. This can lead to mail data theft, lateral movement, and persistent access.

Attack surface

The vulnerability is network-reachable (AV:N) with no privileges or user interaction required per the CVSS vector, but exploitation depends on the ability to set or influence the im_convert_path or im_identify_path configuration values. In practice this means an attacker needs a path to modify those settings, such as a separate configuration flaw or administrative access, which the record does not detail.

Exploitation

CVE-2020-12641 is in CISA's KEV catalog with a due date of 2023-07-13, and EPSS shows a 30-day probability of 0.84336 (99.685th percentile). A public exploit reference is listed, and no ransomware campaign use is documented.

What to do

  • Upgrade Roundcube Webmail to 1.4.4 or later (or the corresponding fixed 1.3.11 / 1.2.10 releases) immediately.
  • If immediate upgrade is not possible, restrict access to Roundcube administration and configuration interfaces to trusted networks and accounts.
  • Audit im_convert_path and im_identify_path settings for unexpected or attacker-controlled values and reset them to trusted binaries.
  • Apply vendor patches for openSUSE backports and Leap packages where Roundcube is bundled.
  • Monitor for unexpected child processes spawned by the web server user, especially ImageMagick-related binaries.

Detection

  • Search web server and Roundcube logs for requests to rcube_image.php with unusual parameters or shell metacharacters.
  • Monitor process creation events where the web server user spawns shells or unexpected commands (e.g., sh, bash, convert, identify).
  • Alert on changes to Roundcube configuration files, particularly im_convert_path and im_identify_path.
  • Correlate outbound network connections from the Roundcube host with process execution by the web server account.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-12641 to the Known Exploited Vulnerabilities catalog on 22 June 2023 as "Roundcube Webmail Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 July 2023.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-12641 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2020-16846SaltStack Salt API shell injection via crafted web requestsSaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. T…KEVEPSS 100%analysed9.8CVE-2020-11651SaltStack Salt master authentication bypass in ClearFuncsSaltStack Salt before 2019.2.4 and 3000 before 3000.2 fails to properly validate method calls in the salt-master ClearFuncs class, allowing remote un…KEVEPSS 97%analysed9.8CVE-2020-1938Apache Tomcat AJP connector file read and JSP execution flawApache Tomcat shipped an AJP Connector enabled by default that listened on all configured IP addresses, and Tomcat treats AJP connections as more tru…KEVEPSS 99%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.6CVE-2020-15999FreeType heap buffer overflow in Chrome via crafted HTML pageFreeType contains a heap buffer overflow reachable through a crafted HTML page in Google Chrome prior to 86.0.4240.111. The flaw is an out-of-bounds …KEVEPSS 44%analysed9.3CVE-2024-42009Roundcube Webmail desanitization XSS in message_body()Roundcube Webmail through 1.5.7 and 1.6.x through 1.6.7 contains a cross-site scripting flaw caused by a desanitization issue in message_body() in pr…KEVEPSS 83%analysed8.8CVE-2025-49113Roundcube Webmail PHP Object Deserialization RCE via _from ParameterRoundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 fails to validate the _from parameter in program/actions/settings/upload.php, allowing PHP ob…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2020-12641), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.