CVE

Roundcube ImageMagick RCE (CVE-2020-12641)

Flag Roundcube Webmail hosts for CVE-2020-12641 by reading the version from GET /CHANGELOG. Floor 1.4.4. No ImageMagick write and no RCE.

AuthorTrickest
100%

Notes on this workflow

CVE-2020-12641 — Roundcube Webmail Cmd Injection

What this checks: whether a Roundcube Webmail host runs a version affected by unauth version leak for authenticated OS command injection RCE. Read-only: it fingerprints Roundcube Webmail and reads the version, no exploitation.

3. Detection — reads the Roundcube Webmail version from the version exposed at /CHANGELOG, compares to 1.4.4. Flags vulnerable on an affected build. No exploitation.

1. Target List — paste your Roundcube Webmail URLs here, one per line (e.g. https://host.example.com).

Overview

This workflow finds Roundcube Webmail and sorts each host by whether its version falls below the CVE-2020-12641 FIXED floor. CVE-2020-12641 is remote code execution through ImageMagick configuration on vulnerable Roundcube builds. This check never writes an ImageMagick policy and never runs a command. Give it hostnames, IP addresses, or URLs you are authorised to test. The workflow GETs /CHANGELOG, fingerprints Roundcube from that changelog text, parses the version, and compares it to floor 1.4.4. Every host comes back affected or not, so a fleet advisory becomes an evidenced list for exposure management. An affected row is a version signal only.

Run it on a schedule when webmail nodes lag just under 1.4.4. A host that stayed on 1.4.3 after the advisory is the reason the same fingerprint stays useful.

Pipeline

  1. Read the target list. Hosts, URLs, or ranges, one per line, become the scope.
  2. GET /CHANGELOG on each host and fingerprint Roundcube from the changelog body that exposes the product version.
  3. Parse the version and compare it to the CVE-2020-12641 floor 1.4.4 in the graph.
  4. Collect the per-host rows: product match, version, vulnerable flag, and any fetch error.
  5. Emit the summary counts: hosts checked, product hits, vulnerable, and errors.

Inputs

  • Target scope. Hostnames, IP addresses, CIDR ranges, or URLs, one per line. Full URLs and host:port entries work too, since the workflow normalizes each into a bare host. Point it at scope you are authorised to test.

Outputs

  • results.jsonl. One row per host: URL, whether Roundcube was detected, the version read, the vulnerable flag, and detail text.
  • findings.jsonl. The same per-host verdict shaped for triage, with severity set from the vulnerable flag.
  • summary.json. Counts across the list: targets, product hits, vulnerable, and errors, plus the detection notes from the graph.

Integrations

  • HTTP. Unauthenticated GET of /CHANGELOG only. No ImageMagick write and no RCE payload.

Sample output

The records below are illustrative and do not come from a real run. They show one Roundcube host below the CVE-2020-12641 floor, one at or above it, and one host that is not the product.

urlis_productproduct_versionvulnerabledetail
https://webmail.example.comtrue1.4.3truebelow fixed release 1.4.4
https://webmail.example.orgtrue1.4.4falseat or above fixed release
https://shop.example.netfalsenullfalsenot identified as Roundcube Webmail
{"cve": "CVE-2020-12641", "total_targets": 3, "product_detected": 2, "vulnerable": 1, "errors": 0}

FAQ

Which Roundcube versions does this flag?

Builds below floor 1.4.4, the single FIXED floor coded in the graph. The compare uses the version string /CHANGELOG itself served.

Does an affected row mean ImageMagick RCE worked?

No. The check only GETs /CHANGELOG and reads the version. It does not write ImageMagick configuration and it does not confirm RCE.

Is this check safe on production?

Yes. It is a read-only unauthenticated GET of the public changelog. It does not authenticate or modify configuration.

Does the check need credentials?

No. It fingerprints the public changelog the way an external scanner would.

What is CVE-2020-12641?

Remote code execution in Roundcube Webmail through ImageMagick configuration on vulnerable builds. This workflow maps hosts to that CVE by version exposure only.

Get a personalized demo

See Trickest in Action

A 30-minute walkthrough. We map the platform to your stack and answer pricing and deployment questions for your environment.