CVE-2024-42009 is a critical cross-site scripting (XSS) vulnerability in Roundcube webmail with a CVSS score of 9.3. Exploitation requires the victim to open a crafted email in the Roundcube client, allowing attackers to execute arbitrary JavaScript in the victim's browser context. This flaw was exploited by the China-aligned cluster UNK_MassTraction to steal credentials and initiate further compromise.