CVE-2025-49113 is a vulnerability in Roundcube webmail servers that was exploited by the Lazarus Group to install a previously undocumented PHP web shell called RelayShell. This allowed the attackers to use compromised servers as command-and-control infrastructure.