
Cross-site Scripting (XSS) - Stored (CWE-79)CVSS 6.7€0
Stored XSS in attachment-display exploitable through SameSite
aikido_security
Disclosed on HackerOne · April 19, 2026
Publicly disclosed report · by aikido_security
View original on HackerOneSummary:
The compose attachments preview endpoint renders user-uploaded HTML files inline without a restrictive Content Security Policy, allowing JavaScript execution. By uploading an HTML file and opening it via display-attachment, the script runs in the Roundcube origin. Attacking a user is only possible by setting cookies on the domain, which can be done from any subdomain of the site where Roundcube is hosted.
Steps To Reproduce:
- Set up a local Roundcube instance on an IP address (eg. 127.0.0.1)
- Edit
C:\Windows\System32\drivers\etc\hostson Windows or/etc/hostson Unix to contain the following entries: