Executive brief
FreeScout is an open-source help desk and shared inbox platform. A security flaw in its application logging feature allows an administrative user to download sensitive files from the underlying server that should be restricted. This could lead to the exposure of system configuration files, credentials, or other private data stored on the server.
Technical details
A path traversal vulnerability exists in FreeScout's `Manage -> Logs -> App Logs` feature due to improper path resolution logic in the bundled `rap2hpoutre/laravel-log-viewer` override. The `pathToLogFile` method in `LaravelLogViewer.php` checks if a user-provided absolute path exists before applying directory restrictions, allowing the check to be bypassed. An attacker with administrative privileges and knowledge of the `APP_KEY` (required to forge a valid Laravel-encrypted `dl` parameter) can exploit this to read any file on the server accessible to the PHP process, such as `/etc/passwd` or environment configuration files. The issue is fixed in version 1.8.224.
Affected products
- freescout-help-desk FreeScout < 1.8.224
Timeline
- 2026-06-10: advisory: GitHub Security Advisory published by vendor
- 2026-07-20: disclosed: CVE published to NVD