Roundcube 1.7.2 closes high-impact XSS and SSRF issues, a reminder that webmail platforms sit where untrusted email content and server-side network access can become the same attack surface.
A security update for Roundcube 1.7.2 shows how browser-facing mail code can turn plain text, URL fetching, and legacy attachments into high-risk attack surfaces.