Roundcube Webmail Security Update: 12 Vulnerabilities Fixed in 1.7.4 and 1.6.19

Published by

Roundcube Webmail has issued emergency security updates for versions 1.7.4 and 1.6.19, fixing a total of 12 vulnerabilities including critical issues like email header injection and a zero-click stored XSS vulnerability. The updates, signed by lead maintainer Aleksander Machniak, are deemed stable and are highly recommended for all productive installations. Admins are urged to update immediately, and Nextcloud users need to verify their bundled Roundcube package version to ensure security. The vulnerabilities were reported by a community of researchers, and the project employs an advisory disclosure model without formal CVE assignments, emphasizing the importance of monitoring GitHub release notes for updates



Roundcube Webmail Security Update: 12 Vulnerabilities Fixed in 1.7.4 and 1.6.19

Roundcube Webmail has released emergency security updates for its 1.7.4 and 1.6.19 branches, addressing 12 recently reported vulnerabilities. The patches fix critical issues including email header injection that could enable spoofing, an SSRF bypass in the CSS proxy, and a zero-click stored XSS triggered by TNEF attachments. Lead maintainer Aleksander Machniak signed the releases, which the project describes as stable and recommended for all productive installations immediately. Admins should update now, while Nextcloud users must also verify their bundled Roundcube package version to ensure they are on the latest secure build.

Roundcube Webmail Security Update: 12 Vulnerabilities Fixed in 1.7.4 and 1.6.19 @ Linux Compatible