Executive brief
FreeScout, an open-source help desk and shared inbox platform, is vulnerable to a flaw that allows attackers to manipulate website links and resource locations. By sending a specially crafted request, an attacker can cause the application to generate links that point to malicious websites or load external content from unauthorized servers. This could be used to trick users into visiting phishing sites or to redirect legitimate traffic to attacker-controlled infrastructure, potentially damaging a company's reputation or compromising user credentials.
Technical details
FreeScout prior to version 1.8.211 fails to properly validate the HTTP Host header when generating absolute URLs for redirects, navigation links, and static assets (such as images and favicons). An unauthenticated remote attacker can manipulate the Host header in a request to inject an arbitrary domain, which the application then reflects in its response (e.g., in the Location header or HTML body). This leads to Open Redirect (CWE-601) and External Resource Loading (CWE-829) vulnerabilities. The issue was addressed by implementing the 'TrustHosts' middleware to restrict the application to authorized hostnames.
Affected products
- freescout-help-desk FreeScout < 1.8.211
Timeline
- 2026-03-28: patched: Version 1.8.211 released
- 2026-03-30: advisory: GitHub Security Advisory published
- 2026-03-31: disclosed: CVE published to NVD