Repository navigation
Security: freescout-help-desk/freescout
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
State-changing conversation clone reachable via unauthenticated-CSRF GET request (CWE-352), sibling of GHSA-5vw8-4wxh-6mprGHSA-qp58-4g6r-qq78 published
Sep 26, 2026 by freescout-help-deskModerate -
Retained website notifications disclose current thread content after mailbox access revocationGHSA-6545-8c3f-pp6w published
Sep 26, 2026 by freescout-help-deskModerate -
Delayed email notifications disclose post-revocation conversation content to former mailbox membersGHSA-2j2c-g32w-96vm published
Sep 26, 2026 by freescout-help-deskModerate -
Draft lifecycle authorization bypass deletes existing conversation historyGHSA-6ff4-3w2c-mjj8 published
Sep 26, 2026 by freescout-help-deskHigh -
Archived mailbox member can permanently purge hidden Spam and Deleted conversationsGHSA-59v9-2qvg-cxw8 published
Sep 26, 2026 by freescout-help-deskHigh -
Unauthenticated installer final page discloses .env after manual FreeScout installationGHSA-3gv6-4vmm-79pj published
Sep 26, 2026 by freescout-help-deskHigh -
Incomplete fix for GHSA-6w8v: SSRF guard bypassed via IPv6 transition addresses (6to4/NAT64/Teredo)GHSA-v5xm-qw3f-qm98 published
Sep 4, 2026 by freescout-help-deskHigh -
Incomplete fix for CVE-2026-40496: legacy MD5 attachment tokens (`token_type=2`)GHSA-89ww-mfww-5vr6 published
Sep 4, 2026 by freescout-help-deskHigh -
FreeScout ZIP extraction follows a final-component symlinkGHSA-rw7g-qq32-c669 published
Aug 29, 2026 by freescout-help-deskHigh