Roundcube 1.6.3 fixes a cross-site scripting issue in handling of linkrefs in plain text messages. References: https://roundcube.net/news/2023/09/15/security-update-1.6.3-released
Created roundcubemail tracking bugs for this issue: Affects: fedora-all [bug 2239448]