NULL CATHEDRAL · Mar 18, 2026
Roundcube round two: three more sanitizer bypasses
0Sign in to vote or save
This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
Three more bypasses in Roundcube's HTML sanitizer: SMIL animation attributes load remote resources, unquoted body backgrounds enable CSS injection, and position:fixed !important enables phishing overlays.
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.