Prototype Pollution Vulnerability in FreeScout Help Desk Software
CVE-2026-53592

4.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-53592?

FreeScout, a free help desk and shared inbox application built on the Laravel framework, contains a Prototype Pollution vulnerability due to insufficient sanitization in the getQueryParam function located in /public/js/main.js. Although the initial mitigation in version 1.8.139 aimed to block top-level __proto__ keys, it inadequately addresses nested form inputs, allowing attackers to exploit this flaw by injecting malicious payloads into the Object.prototype. Users are advised to update to version 1.8.223, which includes a more comprehensive fix to this critical issue.

Affected Version(s)

freescout < 1.8.223

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.