started · updated
Roundcube Webmail releases emergency security updates for 12 vulnerabilities
Roundcube Webmail has released emergency security updates for its 1.7.4 and 1.6.19 branches to address 12 recently reported vulnerabilities. The patches target a variety of flaws, including email header injection, SSRF bypasses in the CSS proxy, and a zero-click stored cross-site scripting (XSS) vulnerability triggered by TNEF attachments.
Specific vulnerabilities include CSS declaration smuggling, remote content blocking bypasses, and issues within the SQL address book regarding contact group membership. The project, with releases signed by lead maintainer Aleksander Machniak, describes these builds as stable and recommends that all productive installations update immediately. Users of Nextcloud are also advised to verify their bundled Roundcube package versions to ensure they are running the latest secure builds.