CVE-2026-107393 — FreeScout is a self-hosted help desk and shared mailbox.
Description
FreeScout is a self-hosted help desk and shared mailbox. Prior to 1.8.235, when APP_CLOUDFLARE_IS_USED is enabled, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts and stores the spoofed value in the activity log. LogsMonitor inserts the value into an administrator alert email without HTML escaping, allowing injected HTML to execute when an administrator opens the email. This issue is fixed in version 1.8.235.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
Required
User Interaction
S
Changed
Scope
C
Low
Confidentiality
I
Low
Integrity
A
None
Availability
References
- advisory[email protected]https://github.com/freescout-help-desk/freescout/commit/0f41f5cabb581de156ec8eb344ff6c0e6e0cc66a
- advisory[email protected]https://github.com/freescout-help-desk/freescout/releases/tag/1.8.235
- advisory[email protected]https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-9cm3-qvj2-8hg4
Related threats
same CWE or vendorCVE-2026-84244 — IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search resu…
CVE-2026-84244 · 2h ago
PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
CVE-2026-61433 · 3h ago
CVE-2026-40804 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kodezen LLC aBlocks ablocks allows Reflected …
CVE-2026-40804 · 3h ago
CVE-2026-107380 — savg-sanitizer is a PHP SVG/XML sanitizer.
CVE-2026-107380 · 4h ago
CVE-2026-107303 — JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures.
CVE-2026-107303 · 4h ago
CVE-2026-104078 — Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute …
CVE-2026-104078 · 5h ago