Be notified of new releases
Create your free GitHub account today to subscribe to this repository for new releases and build software alongside 31 million developers.Sign up
This is a security update to the stable version 1.2. It fixes a recently reported vulnerability allowing IMAP command injection via a GET parameters. More details about this are published under
The second fix is about a missed remote content blocking on HTML messages with specially crafted image and style tags.
We strongly recommend to update all productive installations of Roundcube 1.1.x.
Please do backup your data before updating!
- Don't ignore (global) userlogins/sendmail logs in per_user_logging mode
- Fix security issue in remote content blocking on HTML image and style tags (#6178)
check_request()bypass in places using
- Fix possible IMAP command injection vulnerability [CVE-2018-9846] (#6229)