Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Roundcube-CVE-2025-49113 — Proof-of-concept to CVE-2025-49113 | Kitploit
Tools/GitHubGitHub/biitts/roundcube-cve-2025-49113
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed TeamingPayload Development
GitHubbiitts/roundcube-cve-2025-49113

Roundcube-CVE-2025-49113

Proof-of-concept to CVE-2025-49113

View Repository
6161 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Roundcube RCE Exploit (CVE-2025-49113)

A fully functional proof-of-concept exploit for CVE-2025-49113


🧠 Summary

CVE-2025-49113 is an The vulnerability is the result of a logic flaw in the application's session parser, which allows insecure deserialization of PHP objects. Authenticated users can exploit this issue to execute arbitrary commands on the server.


🔥 Impact

An attacker with valid credentials (even low-privileged user accounts) can exploit this flaw to:

  • Execute arbitrary system commands.
  • Establish reverse shells or deploy persistence.
  • Move laterally within the internal network if Roundcube is self-hosted.

🧩 Vulnerability Details

  • Type: Insecure Deserialization → Remote Code Execution
  • Component: PHP backend (mail processing or plugin loading logic)
  • Conditions: Authenticated session (cookie or login), crafted serialized payload
  • Exploit Primitive: PHP unserialize() with attacker-controlled input and loaded gadgets

✅ Affected Versions

  • 1.5.x: All versions from 1.5.0 to 1.5.9
  • 1.6.x: All versions from 1.6.0 to 1.6.10

Versions prior to 1.5.0 have not been tested, but are potentially vulnerable if backported plugins or features are present.


⚙️ Exploit Requirements

  • Python ≥ 3.7
  • PHP ≥ 7.4 (used for local payload crafting)
  • Python libraries listed in requirements.txt

💻 Setup & Installation

Clone the repository and install the required dependencies:

git clone https://github.com/BiiTts/Roundcube-CVE-2025-49113.git
cd roundcube-rce-CVE-2025-49113
pip install -r requirements.txt

🔥 Execute

python3 roundcube_exploit.py http://roundcube.local/ username password "cmd"

💻 References

https://fearsoff.org/research/roundcube

https://nvd.nist.gov/vuln/detail/CVE-2025-49113

https://hakaisecurity.io/por-tras-da-falha-erro-de-logica-no-parser-de-sessao-do-roundcube-cve-2025-49113/research-blog/

Download Tool