Nixpkgs Security Tracker

Login with GitHub

Details of issue NIXPKGS-2026-0244

NIXPKGS-2026-0244
published on 15 Feb 2026
updated 3 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package ayatana-webmail
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block …

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.

Affected products

Webmail
  • <1.5.13
  • <1.6.13
Issue write-up: https://nullcathedral.com/posts/2026-02-08-roundcube-svg-feimage-remote-image-bypass/
Upstream patch: https://github.com/roundcube/roundcubemail/commit/26d7677471b68ff2d02ebe697cb606790b0cf52f