CVE-2026-75003CWE-669

CVE-2026-75003

Medium · published August 17, 2026

CVSS v3.1
5.8
EPSS
0%
Percentile
23.1
In the wild
Unconfirmed
What it is

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

The record
Technical detail
CVSS v3.1
5.8 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00307 · 23.1th percentile
Weakness
CWE-669 · Incorrect Resource Transfer Between Spheres
Published
2026-08-17T17:16Z
References (5)
EPSS history
Timeline
  • 17 AUG 12:50Z
    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking…
    cvelistv5