Executive brief
FreeScout is an open-source help desk and shared inbox platform. A security flaw allows former staff members to modify messages or internal notes they previously wrote, even after their access to a specific mailbox has been revoked by an administrator. This could allow a disgruntled or former employee to alter the audit trail of customer communications or internal records without authorization.
Technical details
An improper authorization vulnerability exists in the ThreadPolicy::edit method of FreeScout. While the application checks if a user is the author of a thread and has the general 'PERM_EDIT_CONVERSATIONS' permission, it fails to verify if the user still maintains active membership/access to the specific mailbox containing that thread for certain message types (TYPE_MESSAGE and TYPE_NOTE). An attacker with low-privileged credentials who previously had access to a mailbox can send a crafted POST request to the AJAX endpoint to overwrite thread content. This bypasses the intended access control logic where removal from a mailbox should terminate all interaction rights. The issue is resolved in version 1.8.221 by adding a 'userHasAccessToMailbox' check to the affected policy branch.
Affected products
- FreeScout FreeScout < 1.8.221
Timeline
- 2026-05-28: advisory: GitHub Security Advisory published
- 2026-05-29: disclosed: NVD publication date
- 2026-05-29: patched: Vulnerability fixed in version 1.8.221