This release includes 4 security fixes for security teams reviewing exposed deployments.
Topics
+8 more
Affected surfaces
ReleasePort's take
Moderate signalVersion 1.8.224 of FreeScout introduces several security enhancements: throttling file‑upload routes, fixing empty invite_hash during user setup, improving log‑file download logic, and restricting .pht uploads.
Why it matters: All four fixes have a severity score of 90; addressing them prevents abuse of upload endpoints, ensures reliable user onboarding, safeguards log retrieval, and blocks potentially malicious .pht files. Operators should apply the update promptly to mitigate these high‑severity risks.
Summary
AI summaryMultiple security fixes including throttling file uploads, fixing invite_hash issues, and enforcing CSP in browsers.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Adds throttling to file upload routes (GHSA-ph4f-2jhx-q76w) Adds throttling to file upload routes (GHSA-ph4f-2jhx-q76w) Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Security | Critical |
Fixes empty invite_hash during user setup (GHSA-jqj5-r72v-v29g) Fixes empty invite_hash during user setup (GHSA-jqj5-r72v-v29g) Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Security | Critical |
Improves downloading log files logic (GHSA-858x-8f77-9vc5) Improves downloading log files logic (GHSA-858x-8f77-9vc5) Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Security | Critical |
Restricts upload of .pht files (GHSA-27vp-fpg8-j8wv) Restricts upload of .pht files (GHSA-27vp-fpg8-j8wv) Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Feature | Medium |
Enables browser check; blocks browsers without CSP support Enables browser check; blocks browsers without CSP support Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Medium |
Improves sanitizing of customer Websites field Improves sanitizing of customer Websites field Source: llm_adapter@2026-06-06 Confidence: high |
— |
Full changelog
Fixed
- Added throttling to file upload routes (Security: GHSA-ph4f-2jhx-q76w)
- Fixed user-setup empty
invite_hashissue (Security: GHSA-jqj5-r72v-v29g) - Improved downloading log files logic (Security: GHSA-858x-8f77-9vc5)
- Restricted
.phtfiles upload (Security: GHSA-27vp-fpg8-j8wv) - Improved sanitizing customer Websites field.
- Enabled browser check - now it will be impossible to access FreeScout instance from a browser which does not support CSP.
Security Fixes
- GHSA-ph4f-2jhx-q76w — Added throttling to file upload routes
- GHSA-jqj5-r72v-v29g — Fixed user-setup empty `invite_hash` issue
- GHSA-858x-8f77-9vc5 — Improved downloading log files logic (Security)
- GHSA-27vp-fpg8-j8wv — Restricted `.pht` file uploads
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About freescout
FreeScout — Free self-hosted help desk & shared mailbox (Zendesk / Help Scout alternative)
Beta — feedback welcome: [email protected]