The Roundcube Webmail suite
91%
Total Score
88
100
100
90
The top contributor made 68.75% of recent commits, which is a concentration risk. However, 13 contributors were active and the repository is organization-owned, making handoff capacity more credible; the net effect is a moderate caution rather than a severe risk.
Four workflows declare read-only permissions, but one workflow lacks top-level permissions and two bot workflows declare write access. This is a workflow-hygiene concern, though the separate dangerous-workflow analysis found no exploit-pattern indicators.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-988498 roundcube/roundcubemail is vulnerable to Remote Code Execution (RCE) in versions 1.6.0 - 1.7.2. | 1.6.0 - 1.7.2 | High |
CVE-2026-35539 roundcube/roundcubemail is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.7-beta - 1.7-rc5. | 1.7-beta - 1.7-rc5 | Medium |
CVE-2026-35540 roundcube/roundcubemail is vulnerable to Incorrect Resource Transfer Between Spheres in versions 1.7-beta - 1.7-rc5. | 1.7-beta - 1.7-rc5 | Medium |
CVE-2026-35538 roundcube/roundcubemail is vulnerable to Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in versions 1.7-beta - 1.7-rc5. | 1.7-beta - 1.7-rc5 | Low |
CVE-2026-35537 roundcube/roundcubemail is vulnerable to Deserialization of Untrusted Data in versions 1.7-beta - 1.7-rc5. | 1.7-beta - 1.7-rc5 | Low |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pear/net_smtp Version ~1.12.0 | — | — |
mlocati/ip-lib Version ^1.22.0 | — | — |
pear/auth_sasl Version ~1.2.0 | — | — |
pear/crypt_gpg Version ~1.7.0 | — | — |
pear/mail_mime Version ~1.10.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.