How to Safely Upgrade Roundcube to 1.6.11 on HestiaCP (Security Fix)

Hi everyone,

With the recent security vulnerability affecting Roundcube versions 1.6.x and 1.5.x (except 1.6.11 and 1.5.10), I want to update my installation to Roundcube 1.6.11.

I tried running v-add-sys-roundcube hoping it would fetch the latest version, but it seems HestiaCP currently provides only version 1.6.10:

root@srv1 ~ # v-add-sys-roundcube
Error: Installed version (1.6.10) is equal to the available version (1.6.10)

Is there an official or recommended guide for manually upgrading Roundcube to 1.6.11 without breaking future HestiaCP-managed updates or the integration?

Any help or best practices for doing this safely would be greatly appreciated.

Reference:
:link: Security updates 1.6.11 and 1.5.10 released

Thanks in advance!

Hi @ahmedhaseeb

Check this post:

1 Like