Executive brief
FreeScout is an open-source help desk and shared inbox platform. A flaw in the password reset system allows unauthorized individuals to identify which email addresses belong to registered staff members. This information can be used to build target lists for phishing attacks or social engineering, potentially compromising the security of the help desk.
Technical details
A response discrepancy vulnerability (CWE-203/CWE-204) exists in the password reset endpoint of FreeScout prior to version 1.8.219. When a reset request is submitted, the application returns a success message with a specific CSS class for valid emails, while returning an error message and a different CSS class for invalid emails. Because there is no rate limiting on this endpoint, an unauthenticated attacker can perform automated network-based enumeration to harvest valid agent email addresses. This vulnerability serves as a prerequisite for targeted phishing or further impersonation attacks. The issue is resolved in version 1.8.219 by normalizing the response.
Affected products
- FreeScout FreeScout < 1.8.219
Timeline
- 2026-05-12: advisory: GitHub Security Advisory published
- 2026-05-29: disclosed: NVD publication date
- 2026-05-12: patched: Fix released in version 1.8.219