Executive brief
FreeScout is an open-source help desk and shared inbox platform used by businesses to manage customer support communications. A security flaw allows unauthorized individuals to download email attachments without logging in or providing a valid security token. This could lead to the exposure of sensitive customer data, such as contracts, invoices, or personal documents, if they were uploaded using older versions of the software.
Technical details
A logical flaw exists in the `downloadAttachment` method within `app/Http/Controllers/OpenController.php`. The code explicitly skips token validation if an attachment's `token_type` is set to `1` (`TOKEN_TYPE_LEGACY`). Because the attachment download route is registered without authentication middleware and file storage paths are computed deterministically based on the attachment's database ID, an attacker can enumerate IDs to derive paths and download legacy files. This affects installations upgraded from older versions where legacy tokens are still present in the database. The vulnerability is addressed in version 1.8.221 by removing the legacy bypass.
Affected products
- freescout-help-desk FreeScout < 1.8.221
Timeline
- 2026-06-01: advisory: GitHub Security Advisory published
- 2026-07-20: disclosed: CVE published to NVD