Hello, good afternoon. We received a report from one of our clients about a possible vulnerability in Roundcube affecting versions < 1.5.10 and 1.6.0–1.6.10.
Issue link: CVE-2025-49113 – Post-Auth Remote Code Execution in Roundcube via PHP Object Deserialization.
My /usr/local/hestia/install/upgrade/upgrade.conf file has:
# Set version of RoundCube (Webmail) to update during upgrade if not already installed
# Note: only applies to "non-apt installs >= 1.4.0 or manually phased out"
rc_v='1.6.11'
I run the update command:
But it doesn’t update—Roundcube stays on version 1.6.8.
Any idea why the rc_v value isn’t being applied or how to force the update to 1.6.11?
Important Warning: Don’t trust the automatic file updates to resolve everything magically. Always verify that your version is actually updated to 1.6.11 after following these steps.
Prerequisites
Root or sudo access to your server
Basic command line knowledge
Roundcube installation (typically in /var/lib/roundcube/)