Unauthenticated Message Injection in FreeScout Help Desk Software
CVE-2026-53591
8.6HIGH
What is CVE-2026-53591?
The FreeScout help desk software, built on the Laravel framework, is subject to a message injection vulnerability. Prior to version 1.8.223, an unauthenticated attacker can exploit this flaw by sending a specially crafted email to the helpdesk's public address. This allows the attacker to inject messages into existing support conversations without needing any credentials or prior access. The injected message appears as a legitimate response from a customer, reopening the conversation and altering the last_reply_from field to reflect the attacker's identity. This vulnerability underscores the importance of updating to version 1.8.223 to maintain the integrity of communications and security within your support channels.
Affected Version(s)
freescout < 1.8.223
