Roundcube Webmail <1.5.13 / <1.6.13 allows attackers to force remote image loads via SVG feImage
Roundcube's HTML sanitizer doesn't treat SVG feImage href as an image source. Attackers can bypass remote image blocking to track email opens.
Date: 2026-02-08
Last Modified: 2026-02-08
Tags: vulnerability, roundcube, svg, email-security
URL: https://nullcathedral.com/posts/2026-02-08-roundcube-svg-feimage-remote-image-bypass/
------------------------------------------------------------------------
TL;DR: Roundcube's rcube_washtml sanitizer blocked external resources on
, , and