# CVE-2024-42009 — Roundcube Webmail

**CISA KEV**

> As of 2025-10-21, CVE-2024-42009 is a CRITICAL-severity vulnerability in Roundcube Webmail, CVSS v3.1 9.3, EPSS 83.3% (99.6th percentile). It is listed in the CISA Known Exploited Vulnerabilities catalog (added 2025-06-09), with a US federal remediation deadline of 2025-06-30. Threadlinqs Intelligence links 2 tracked threat campaigns to CVE-2024-42009, most recently “UNK_MassTraction: China-Aligned Actor Exploits Roundcube CVE-2024-42009 & CVE-2025-49113 to Deploy IceCube Stealer and VShell Against University Physics Departments”.

**Last updated:** 2025-10-21

## What is CVE-2024-42009?

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

The record classifies CVE-2024-42009 under weakness class [CWE-79](https://cwe.mitre.org/data/definitions/79.html). Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs no prior authentication, needs a user to take an action first, and has high impact on confidentiality, integrity. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 769 days ago.

## Severity and exploitation probability

- **CVSS v3.1 base score:** 9.3 — CRITICAL (`CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N`)
- **EPSS (FIRST):** 83.3% probability of exploitation in the next 30 days, higher than 99.6% of all scored CVEs
- **CISA KEV:** Listed since 2025-06-09, federal remediation deadline 2025-06-30
- **Threadlinqs priority:** 9/10 — CISA KEV-listed, which Threadlinqs floors at 9
- **Published:** 2024-08-05, last modified 2025-10-21

## Is CVE-2024-42009 being exploited?

CISA added CVE-2024-42009 to the Known Exploited Vulnerabilities catalog on 2025-06-09, which means the agency holds evidence of exploitation in the wild; US federal civilian agencies had to remediate it by 2025-06-30 under BOD 22-01. Weaponised exploit code for CVE-2024-42009 is publicly available. 7 public proof-of-concept repositories are tracked for this identifier. A ProjectDiscovery Nuclei detection template exists (`http/cves/2024/CVE-2024-42009.yaml`). It currently carries a trending score of 45 in the Threadlinqs vulnerability feed.

- [DaniTheHack3r/CVE-2024-42009-PoC](https://github.com/DaniTheHack3r/CVE-2024-42009-PoC) (github)
- [0xbassiouny1337/CVE-2024-42009](https://github.com/0xbassiouny1337/CVE-2024-42009) (github)
- [Bhanunamikaze/CVE-2024-42009](https://github.com/Bhanunamikaze/CVE-2024-42009) (github)
- [ZaidArif47/CVE-2024-42009](https://github.com/ZaidArif47/CVE-2024-42009) (github)
- [Shubhankargupta691/CVE-2024-42009](https://github.com/Shubhankargupta691/CVE-2024-42009) (github)
- [segunakinsoyinu/CVE-2024-42009-roundcube-xss](https://github.com/segunakinsoyinu/CVE-2024-42009-roundcube-xss) (github)
- [trickest/cve](https://github.com/trickest/cve/blob/main/2024/CVE-2024-42009.md) (trickest)

## Affected products and versions

- **Roundcube**: Webmail

## How to fix CVE-2024-42009

Vendor advisory: [https://roundcube.net/news/2024/08/04/security-updates-1.6.8-and-1.5.8](https://roundcube.net/news/2024/08/04/security-updates-1.6.8-and-1.5.8). Because CVE-2024-42009 is KEV-listed, US federal civilian agencies were required to apply the vendor fix, or stop using the product, by 2025-06-30. Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.

## Threat activity tracking CVE-2024-42009

2 tracked threats in the Threadlinqs corpus reference CVE-2024-42009, either in the campaign’s CVE list or as an indicator on the campaign record.

- [UNK_MassTraction: China-Aligned Actor Exploits Roundcube CVE-2024-42009 & CVE-2025-49113 to Deploy IceCube Stealer and VShell Against University Physics Departments](https://intel.threadlinqs.com/threat/TL-2026-1259) — HIGH · 2026-07-13
- [UNK_MassTraction Exploits Roundcube XSS/Deserialization Flaws (CVE-2024-42009, CVE-2025-49113) to Spy on Academic Researchers](https://intel.threadlinqs.com/threat/TL-2026-1162) — HIGH · 2026-07-10

## Sources

Enriched from CVE.org, NVD, FIRST EPSS, CISA KEV, GitHub Security Advisories, public proof-of-concept repositories, ProjectDiscovery Nuclei. Last verified by Threadlinqs on 2026-07-13. This product uses the NVD API but is not endorsed or certified by the NVD.

**Other references**

- [github.com](https://github.com/roundcube/roundcubemail/releases)
- [sonarsource.com](https://sonarsource.com/blog/government-emails-at-risk-critical-cross-site-scripting-vulnerability-in-roundcube-webmail/)
- [github.com (1.5)](https://github.com/roundcube/roundcubemail/releases/tag/1.5.8)
- [github.com (1.6)](https://github.com/roundcube/roundcubemail/releases/tag/1.6.8)
- [roundcube.net](https://roundcube.net/news/2024/08/04/security-updates-1.6.8-and-1.5.8)

Canonical: https://intel.threadlinqs.com/cve/CVE-2024-42009
Full detection coverage and IOCs for threats exploiting CVE-2024-42009 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
