Junglewise Threat Intelligence

CVE-2026-53592: FreeScout Prototype Pollution in getQueryParam function

CVE-2026-53592 · Severity: medium · CVSS 4.6 · Published 2026-07-20

Technologies: FreeScout Help Desk FreeScout. Vendors: FreeScout Help Desk.

Executive brief

FreeScout is an open-source help desk and shared inbox platform. A security flaw in its web interface allows an attacker to manipulate the underlying JavaScript environment by sending a specially crafted link to a logged-in user. This could potentially lead to unauthorized changes in how the application behaves, such as redirecting users to malicious sites or stealing sensitive information if combined with other vulnerabilities.

Technical details

A Prototype Pollution vulnerability exists in the `getQueryParam` function within `/public/js/main.js` of FreeScout. While a previous fix (v1.8.139) attempted to block the `__proto__` key, it only checked if the top-level query parameter started with that string. An attacker can bypass this by using nested bracket notation, such as `b[__proto__][polluted]=value`, which the regex fails to catch. This allows an authenticated attacker to inject properties into the global `Object.prototype` via a crafted URL. If the application later uses these polluted properties in a sensitive context, it could lead to DOM-based XSS or other client-side attacks. The issue is fully resolved in version 1.8.223.

Affected products

  • freescout-help-desk FreeScout < 1.8.223

Timeline

  • 2026-06-10: advisory: GitHub Security Advisory published
  • 2026-07-20: disclosed: CVE published to NVD

References