


Perceptive Security
SOC/SIEM Consultancy

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a stored cross-site scripting (XSS) vulnerability in the mailbox si…
Published:
20 april 2026 om 22:00:00
Alert date:
21 april 2026 om 18:10:28
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
FreeScout versions prior to 1.8.213 contain a stored cross-site scripting vulnerability in the mailbox signature feature. The vulnerability stems from incomplete HTML sanitization that only blocks four HTML tags but allows dangerous event handler attributes. Authenticated users with signature permissions can inject arbitrary HTML and JavaScript that executes automatically when agents or administrators view conversations. This enables session hijacking, phishing attacks, email exfiltration, and self-propagating worm behavior across mailboxes. The issue is fixed in version 1.8.213.
Technical details
Mitigation steps:
Affected products:
FreeScout
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40568
https://github.com/freescout-help-desk/freescout/commit/1d83e1cffb0bf8d109625313530b36b0f5910b3f
https://github.com/freescout-help-desk/freescout/releases/tag/1.8.213
https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-w2f5-6wcv-677r
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
