HTML Injection Vulnerability in FreeScout Help Desk System
CVE-2026-40565

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
21 April 2026

What is CVE-2026-40565?

FreeScout, a popular self-hosted help desk solution, is impacted by a vulnerability where the linkify() function does not properly escape double-quote characters in URLs within email bodies. This oversight allows attackers to inject arbitrary HTML attributes by breaking out of the href attribute in the generated anchor tags. Users are advised to update to version 1.8.213 or later, which addresses this critical security flaw by ensuring proper encoding of user-input URLs.

Affected Version(s)

freescout < 1.8.213

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.