Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Roundcube-CVE-2025-49113 — Proof-of-concept to CVE-2025-49113 | Kitploit
Tools/GitHubGitHub/biitts/roundcube-cve-2025-49113
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed TeamingPayload Development
GitHubbiitts/roundcube-cve-2025-49113

Roundcube-CVE-2025-49113

Proof-of-concept to CVE-2025-49113

View Repository
6121 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Roundcube RCE Exploit (CVE-2025-49113)

A fully functional proof-of-concept exploit for CVE-2025-49113


🧠 Summary

CVE-2025-49113 is an The vulnerability is the result of a logic flaw in the application's session parser, which allows insecure deserialization of PHP objects. Authenticated users can exploit this issue to execute arbitrary commands on the server.


🔥 Impact

An attacker with valid credentials (even low-privileged user accounts) can exploit this flaw to:

  • Execute arbitrary system commands.
  • Establish reverse shells or deploy persistence.
  • Move laterally within the internal network if Roundcube is self-hosted.

🧩 Vulnerability Details

  • Type: Insecure Deserialization → Remote Code Execution
  • Component: PHP backend (mail processing or plugin loading logic)
  • Conditions: Authenticated session (cookie or login), crafted serialized payload
  • Exploit Primitive: PHP unserialize() with attacker-controlled input and loaded gadgets

✅ Affected Versions

  • 1.5.x: All versions from to
Download Tool
1.5.0
1.5.9
  • 1.6.x: All versions from 1.6.0 to 1.6.10
  • Versions prior to 1.5.0 have not been tested, but are potentially vulnerable if backported plugins or features are present.


    ⚙️ Exploit Requirements

    • Python ≥ 3.7
    • PHP ≥ 7.4 (used for local payload crafting)
    • Python libraries listed in requirements.txt

    💻 Setup & Installation

    Clone the repository and install the required dependencies:

    root@kitploit:~
    git clone https://github.com/BiiTts/Roundcube-CVE-2025-49113.git
    cd roundcube-rce-CVE-2025-49113
    pip install -r requirements.txt
    

    🔥 Execute

    root@kitploit:~
    python3 roundcube_exploit.py http://roundcube.local/ username password "cmd"
    

    💻 References

    https://fearsoff.org/research/roundcube

    https://nvd.nist.gov/vuln/detail/CVE-2025-49113

    https://hakaisecurity.io/por-tras-da-falha-erro-de-logica-no-parser-de-sessao-do-roundcube-cve-2025-49113/research-blog/