
Detailed vulnerability report and exploitation guide for CVE-2025-49113, a PHP object deserialization RCE in Roundcube Webmail, including Metasploit steps and analysis.

⚠️ IMPORTANT NOTICE — RESPONSIBLE USE
This material is for educational and research purposes only.
The use of the information and tools described here for any illegal or malicious activity is strictly prohibited.
The author is not responsible for the misuse of this content.
This repository contains a detailed report on vulnerability CVE-2025-49113, a critical remote code execution (RCE) flaw due to PHP object deserialization affecting Roundcube Webmail versions up to 1.6.10.
The purpose of this project is to serve as an educational and research resource, demonstrating how the vulnerability can be identified and exploited in a controlled environment.
To access the complete information about this vulnerability, including service deployment, exploitation steps with Metasploit Framework, and a detailed analysis, please refer to the following PDF document: