Roundcube vulnerabilities ?
Is cPanel on this?
https://roundcube.net/news/2026/09/06/security-updates-1.6.19-and-1.7.4
Security fixes
- Fix CSS declaration smuggling via un-encoded ampersand emission, reported by Zach Hanley of Horizon3.ai
- Fix CSS property injection via body
backgroundattribute, reported by zenithhostingevan - Fix email header injection via bare CR in the subject field, reported by CVE-Hunter-Leo
- Fix email header injection via C-escape \r in the recipient display name, reported by dogeshark
- Fix email header injection via identity’s organization field, reported by dogeshark
- Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL, reported by nakko
- Fix XSS in the HTML editor using text/enriched part content, reported by Joshua Rogers
- Fix cross-user access in contact group membership (add/remove) in the SQL address book, reported by Joshua Rogers
- Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL, reported by nept1337
- Fix remote content blocking bypass via CSS escapes in FuncIRI attributes, reported by Wahab KHADIR
- Fix remote-content blocker bypass via SVG SMIL src animation
- Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses, reported by faceless0x7 and Harish Annavisamy
-
We sure are! Our team has case CPANEL-56621 open to get this updated!
0 -
It looks like our team has this resolved so it should get included in the next major cPanel release when that happens.
1
Please sign in to leave a comment.
Comments
2 comments