Skip to content

freescout

v1.8.225 Security

This release includes 5 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 5 known CVEs

Topics

customer-support help-desk helpdesk helpdesk-ticketing helpscout laravel
+8 more
osticket-alternative php shared-mailboxes support ticketing ticketing-system zendesk zendesk-alternative

Affected surfaces

auth rce_ssrf deps

ReleasePort's take

Moderate signal
editorial:auto 3h

Version 1.8.225 patches `symfony/routing`, upgrades `symfony/polyfill-intl-idn`, and fixes a path‑traversal flaw in the Log Viewer.

Why it matters: High‑severity CVEs (CVE‑2026‑45065, CVE‑2026‑46644) and a critical GHSA vulnerability require immediate patching to prevent remote code execution and traversal attacks; severity scores exceed 85.

Summary

AI summary

Fixed path traversal in Log Viewer and patched multiple security vulnerabilities.

Changes in this release

Security Critical

Patched `symfony/routing` (CVE-2026-45065)

Patched `symfony/routing` (CVE-2026-45065)

Source: llm_adapter@2026-06-13

Confidence: high

Security Critical

Upgraded `symfony/polyfill-intl-idn` to 1.38.1 (CVE-2026-46644)

Upgraded `symfony/polyfill-intl-idn` to 1.38.1 (CVE-2026-46644)

Source: llm_adapter@2026-06-13

Confidence: high

Security Critical

Fixed path traversal in Log Viewer (GHSA-9ph7-f3hc-95gg)

Fixed path traversal in Log Viewer (GHSA-9ph7-f3hc-95gg)

Source: llm_adapter@2026-06-13

Confidence: high

Security Critical

Improved `Helper::stripDangerousTags()` to strip nested tags (GHSA-jpq8-j69f-mj98)

Improved `Helper::stripDangerousTags()` to strip nested tags (GHSA-jpq8-j69f-mj98)

Source: llm_adapter@2026-06-13

Confidence: high

Security High

Added throttling and authentication in `tools.php` (GHSA-w2p9-3666-vw9j)

Added throttling and authentication in `tools.php` (GHSA-w2p9-3666-vw9j)

Source: llm_adapter@2026-06-13

Confidence: high

Feature Low

Moved option to UI: "_User can see only assigned conversations_" (#701)

Moved option to UI: "_User can see only assigned conversations_" (#701)

Source: llm_adapter@2026-06-13

Confidence: high

Bugfix Medium

Fixed color of texts in logs table (#5442)

Fixed color of texts in logs table (#5442)

Source: llm_adapter@2026-06-13

Confidence: high

Bugfix Medium

Fixed saving mailbox signature by non-admin users (#5443)

Fixed saving mailbox signature by non-admin users (#5443)

Source: llm_adapter@2026-06-13

Confidence: high

Full changelog

Fixed

  • Added throttling and authentication in tools.php (Security: GHSA-w2p9-3666-vw9j)
  • Fixed color of texts in logs table (#5442)
  • Patched symfony/routing (Security: CVE-2026-45065)
  • Upgraded symfony/polyfill-intl-idn to 1.38.1 (Security: CVE-2026-46644)
  • Fixed path traversal in Log Viewer (Security: GHSA-9ph7-f3hc-95gg)
  • Moved option to UI: "User can see only assigned conversations" (#701)
  • Improved Helper::stripDangerousTags() to strip nested tags (Security: GHSA-jpq8-j69f-mj98)
  • Fixed saving mailbox signature by non-admin users (#5443)

Security Fixes

  • GHSA-w2p9-3666-vw9j — added throttling and authentication in `tools.php`
  • CVE-2026-45065 — patched `symfony/routing` dependency
  • CVE-2026-46644 — upgraded `symfony/polyfill-intl-idn` to 1.38.1
  • GHSA-9ph7-f3hc-95gg — fixed path traversal in Log Viewer
  • GHSA-jpq8-j69f-mj98 — improved `Helper::stripDangerousTags()` to strip nested tags

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track freescout

Get notified when new releases ship.

Sign up free

About freescout

FreeScout — Free self-hosted help desk & shared mailbox (Zendesk / Help Scout alternative)

All releases →

Related context

Related CVEs

Earlier breaking changes

  • v1.8.221 Links to attachments uploaded before 2020-03-06 will become unavailable.
  • v1.8.220 Replies to previously received email notifications will not be sent to customers.

Beta — feedback welcome: [email protected]