Executive brief
FreeScout is an open-source help desk and shared inbox platform. A security flaw allows authenticated users to bypass file upload restrictions by using specific file extensions like .pht that were missing from the system's blocklist. An attacker can use this to upload a malicious script and execute commands on the server, potentially leading to a full system takeover, theft of customer data, and access to sensitive database credentials.
Technical details
FreeScout's file upload validation in 'Helper::$restricted_extensions' uses an incomplete denylist that fails to include the '.pht' extension (among others like .phtm and .phps). An authenticated user can send a POST request to '/uploads/upload', which saves the file with its original extension into the web-accessible 'storage/app/public/uploads/' directory. In standard Apache deployments using 'libapache2-mod-php', the default configuration executes '.pht' files as PHP scripts. This allows an attacker to upload a web shell and execute arbitrary OS commands as the 'www-data' user. This vulnerability is a bypass of the previous fix for CVE-2025-48471. The issue is resolved in version 1.8.224.
Affected products
- freescout-help-desk FreeScout < 1.8.224
Timeline
- 2026-06-10: advisory: GitHub Security Advisory published
- 2026-07-20: disclosed: CVE published to NVD