DOC: How to update Roundcube to version 1.6.14 (fixes 8 security vulnerabilities)

Thank you very much, the solution worked perfectly. Now just waiting for their official fix. Cheers!

I’ve opened this issue:

If you want to apply the official fix.

cd /var/lib/roundcube/program/actions/mail/
curl https://raw.githubusercontent.com/roundcube/roundcubemail/6b137adda9b042c3742b0f968692e95ed367d3d1/program/actions/mail/search.php -o search.php

As you applied the workaround, you should revert it:

cd /var/lib/roundcube/program/lib/Roundcube/
mv rcube_imap_generic.php.bak rcube_imap_generic.php

+1 for the above working and thanks to @sahsanu for the write up. I upgraded as root from 1.6.11 direct to 1.6.14.

I assume that after testing the update it is safe to remove the files backed up and moved from the /tmp folder?

this also worked to update Roundcube to 1.6.16 . thanks

I upgraded to 1.7.1

sed -E -i "s/^rc_v='1.*/rc_v='1.7.1'/" /usr/local/hestia/install/upgrade/upgrade.conf

sed -i -E 's/(^disable_functions.*),proc_open(.*$)/\1\2/' /etc/php/$(php -v | head -n1 | grep -o '[0-9]\.[0-9]')/cli/php.ini

sed -i -E 's/(^disable_functions.*),system(.*$)/\1\2/' /etc/php/$(php -v | head -n1 | grep -o '[0-9]\.[0-9]')/cli/php.ini

v-add-sys-roundcube

cd /var/lib/roundcube/
COMPOSER_ALLOW_SUPERUSER=1 composer -n update

If composer not found, then:

v-add-user-composer admin

cd /var/lib/roundcube/
COMPOSER_ALLOW_SUPERUSER=1 /home/admin/.composer/composer -n update

Check version via cli:

grep RCMAIL_VERSION /var/lib/roundcube/program/include/iniset.php | cut -d "'" -f 4

For all, you can’t upgrade from 1.6.x to 1.7.x if the mail templates are not modified, keep that in mind.

I’m not going to update that post anymore, but I’ll keep updating the script to install Roundcube 1.7.x (now it’s updated to install Roundcube 1.7.1):

curl -fsSLm15 https://7j.gg/updrc17 | sudo bash -s --

I should have posted on the 1.7X one. My bad.

My version now is Roundcube Webmail 1.6.15, I don’t use the web version often, and after the update I probably didn’t look at it, today I wanted to read the email and saw it. Has anyone come across and how can I fix it?

Content-Security-Policy: (Report-Only policy) The page’s settings would block a script (script-src-elem) at https://webmail.angellive.ru/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js from being executed because it violates the following directive: “script-src 'unsafe-inline' 'unsafe-eval'” webmail.angellive.ru
Content-Security-Policy: (Report-Only policy) The page’s settings would block a script (script-src-elem) at https://webmail.angellive.ru/cdn-cgi/scripts/7d0fa10a/cloudflare-static/rocket-loader.min.js from being executed because it violates the following directive: “script-src 'unsafe-inline' 'unsafe-eval'” webmail.angellive.ru
Content-Security-Policy: (Report-Only policy) The page’s settings would block a script (script-src-elem) at https://webmail.angellive.ru/program/js/jquery.min.js?s=1774777730 from being executed because it violates the following directive: “script-src 'unsafe-inline' 'unsafe-eval'” rocket-loader.min.js:1:11855
Content-Security-Policy: (Report-Only policy) The page’s settings would block a script (script-src-elem) at https://webmail.angellive.ru/program/js/common.min.js?s=1774777727 from being executed because it violates the following directive: “script-src 'unsafe-inline' 'unsafe-eval'” rocket-loader.min.js:1:11855
Content-Security-Policy: (Report-Only policy) The page’s settings would block a script (script-src-elem) at https://webmail.angellive.ru/program/js/app.min.js?s=1774777727 from being executed because it violates the following directive: “script-src 'unsafe-inline' 'unsafe-eval'” rocket-loader.min.js:1:11855
Content-Security-Policy: (Report-Only policy) The page’s settings would block a script (script-src-elem) at https://webmail.angellive.ru/program/js/treelist.min.js?s=1774777727 from being executed because it violates the following directive: “script-src 'unsafe-inline' 'unsafe-eval'” rocket-loader.min.js:1:11855
Content-Security-Policy: (Report-Only policy) The page’s settings would block a script (script-src-elem) at https://webmail.angellive.ru/program/js/list.min.js?s=1774777727 from being executed because it violates the following directive: “script-src 'unsafe-inline' 'unsafe-eval'” rocket-loader.min.js:1:11855
Content-Security-Policy: (Report-Only policy) The page’s settings would block a script (script-src-elem) at https://webmail.angellive.ru/plugins/newmail_notifier/newmail_notifier.min.js?s=1774777727 from being executed because it violates the following directive: “script-src 'unsafe-inline' 'unsafe-eval'” rocket-loader.min.js:1:11855
Content-Security-Policy: (Report-Only policy) The page’s settings would block a script (script-src-elem) at https://webmail.angellive.ru/plugins/zipdownload/zipdownload.min.js?s=1774777727 from being executed because it violates the following directive: “script-src 'unsafe-inline' 'unsafe-eval'” rocket-loader.min.js:1:11855
Content-Security-Policy: (Report-Only policy) The page’s settings would block a script (script-src-elem) at https://webmail.angellive.ru/plugins/archive/archive.min.js?s=1774777727 from being executed because it violates the following directive: “script-src 'unsafe-inline' 'unsafe-eval'” rocket-loader.min.js:1:11855
Content-Security-Policy: (Report-Only policy) The page’s settings would block a script (script-src-elem) at https://webmail.angellive.ru/plugins/managesieve/managesieve.min.js?s=1774777727 from being executed because it violates the following directive: “script-src 'unsafe-inline' 'unsafe-eval'” rocket-loader.min.js:1:11855
Content-Security-Policy: (Report-Only policy) The page’s settings would block a script (script-src-elem) at https://webmail.angellive.ru/plugins/jqueryui/js/jquery-ui.min.js?s=1774777727 from being executed because it violates the following directive: “script-src 'unsafe-inline' 'unsafe-eval'” rocket-loader.min.js:1:11855
Content-Security-Policy: (Report-Only policy) The page’s settings would block a script (script-src-elem) at https://webmail.angellive.ru/plugins/jqueryui/js/i18n/datepicker-ru.js?s=1774777727 from being executed because it violates the following directive: “script-src 'unsafe-inline' 'unsafe-eval'” rocket-loader.min.js:1:11855
Content-Security-Policy: (Report-Only policy) The page’s settings would block a script (script-src-elem) at https://webmail.angellive.ru/skins/elastic/deps/bootstrap.bundle.min.js?s=1774777731 from being executed because it violates the following directive: “script-src 'unsafe-inline' 'unsafe-eval'” rocket-loader.min.js:1:11855
Content-Security-Policy: (Report-Only policy) The page’s settings would block a script (script-src-elem) at https://webmail.angellive.ru/skins/elastic/ui.min.js?s=1774777728 from being executed because it violates the following directive: “script-src 'unsafe-inline' 'unsafe-eval'” rocket-loader.min.js:1:11855
Content-Security-Policy: (Report-Only policy) The page’s settings would block the loading of a resource (connect-src) at https://webmail.angellive.ru/?_task=mail&_action=list&_refresh=1&_layout=widescreen&_mbox=INBOX&_page=&_remote=1&_unlock=loading1779961980410&_=1779961980177 because it violates the following directive: “connect-src 'none'” jquery.min.js:36:82613
Content-Security-Policy: (Report-Only policy) The page’s settings would block the loading of a resource (connect-src) at https://webmail.angellive.ru/?_task=mail&_action=getunread&_page=1&_remote=1&_unlock=0&_=1779961980178 because it violates the following directive: “connect-src 'none'”

I can access to the webmail:


No access inside

Could you please disable Cloudflare proxy for the webmail and try again?

Disabled, tried from different browsers and in the incognito tab, the same is not accessible, strange this has never happened before

Try to rebuild the webmail domain.

v-rebuild-mail-domain YourUser angellive.ru

If that doesn’t work, upgrade Rouncube to 1.6.16 (you should do it even if it works, it fixes a few security issues).

Okay, now, here’s what’s in the error logs, It didn’t help v-rebuild-mail-domain YourUser angellive.ru

[28-May-2026 10:28:37 UTC] PHP Fatal error:  Uncaught Error: Class "IPLib\Factory" not found in /var/lib/roundcube/program/lib/Roundcube/rcube_utils.php:438
Stack trace:
#0 /var/lib/roundcube/program/lib/Roundcube/rcube_washtml.php(396): rcube_utils::is_local_url()
#1 /var/lib/roundcube/program/lib/Roundcube/rcube_washtml.php(599): rcube_washtml->wash_uri()
#2 /var/lib/roundcube/program/lib/Roundcube/rcube_washtml.php(661): rcube_washtml->dumpHtml()
#3 /var/lib/roundcube/program/lib/Roundcube/rcube_washtml.php(661): rcube_washtml->dumpHtml()
#4 /var/lib/roundcube/program/lib/Roundcube/rcube_washtml.php(730): rcube_washtml->dumpHtml()
#5 /var/lib/roundcube/program/actions/mail/index.php(1004): rcube_washtml->wash()
#6 /var/lib/roundcube/program/actions/mail/index.php(1053): rcmail_action_mail_index::wash_html()
#7 /var/lib/roundcube/program/actions/mail/show.php(738): rcmail_action_mail_index::print_body()
#8 /var/lib/roundcube/program/include/rcmail_output_html.php(1484): rcmail_action_mail_show::message_body()
#9 [internal function]: rcmail_output_html->xml_command()
#10 /var/lib/roundcube/program/include/rcmail_output_html.php(1322): preg_replace_callback()
#11 /var/lib/roundcube/program/include/rcmail_output_html.php(825): rcmail_output_html->parse_xml()
#12 /var/lib/roundcube/program/include/rcmail_output_html.php(654): rcmail_output_html->parse()
#13 /var/lib/roundcube/program/actions/mail/show.php(164): rcmail_output_html->send()
#14 /var/lib/roundcube/program/include/rcmail.php(282): rcmail_action_mail_show->run()
#15 /var/lib/roundcube/index.php(278): rcmail->action_handler()
#16 {main}
  thrown in /var/lib/roundcube/program/lib/Roundcube/rcube_utils.php on line 438
[28-May-2026 10:29:53 UTC] PHP Fatal error:  Uncaught Error: Class "IPLib\Factory" not found in /var/lib/roundcube/program/lib/Roundcube/rcube_utils.php:438
Stack trace:
#0 /var/lib/roundcube/program/lib/Roundcube/rcube_washtml.php(396): rcube_utils::is_local_url()
#1 /var/lib/roundcube/program/lib/Roundcube/rcube_washtml.php(599): rcube_washtml->wash_uri()
#2 /var/lib/roundcube/program/lib/Roundcube/rcube_washtml.php(661): rcube_washtml->dumpHtml()
#3 /var/lib/roundcube/program/lib/Roundcube/rcube_washtml.php(661): rcube_washtml->dumpHtml()
#4 /var/lib/roundcube/program/lib/Roundcube/rcube_washtml.php(730): rcube_washtml->dumpHtml()
#5 /var/lib/roundcube/program/actions/mail/index.php(1004): rcube_washtml->wash()
#6 /var/lib/roundcube/program/actions/mail/index.php(1053): rcmail_action_mail_index::wash_html()
#7 /var/lib/roundcube/program/actions/mail/show.php(738): rcmail_action_mail_index::print_body()
#8 /var/lib/roundcube/program/include/rcmail_output_html.php(1484): rcmail_action_mail_show::message_body()
#9 [internal function]: rcmail_output_html->xml_command()
#10 /var/lib/roundcube/program/include/rcmail_output_html.php(1322): preg_replace_callback()
#11 /var/lib/roundcube/program/include/rcmail_output_html.php(825): rcmail_output_html->parse_xml()
#12 /var/lib/roundcube/program/include/rcmail_output_html.php(654): rcmail_output_html->parse()
#13 /var/lib/roundcube/program/actions/mail/show.php(164): rcmail_output_html->send()
#14 /var/lib/roundcube/program/include/rcmail.php(282): rcmail_action_mail_show->run()
#15 /var/lib/roundcube/index.php(278): rcmail->action_handler()
#16 {main}
  thrown in /var/lib/roundcube/program/lib/Roundcube/rcube_utils.php on line 438

Paste here the steps you used to upgrade Roundcube.

I took here DOC: How to update Roundcube to version 1.6.15 (fixes 1 security vulnerability and 2 regressions)

Show the output of this:

cd /var/lib/roundcube/
COMPOSER_ALLOW_SUPERUSER=1 /home/admin/.composer/composer -n update

If that is the user that has composer installed, great, but you added a space to the command after the user name.

Try this:

cd /var/lib/roundcube && composer require iplib/iplib