Skip to content

freescout

v1.8.230 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

customer-support help-desk helpdesk helpdesk-ticketing helpscout laravel
+8 more
osticket-alternative php shared-mailboxes support ticketing ticketing-system zendesk zendesk-alternative

Affected surfaces

deps rce_ssrf

ReleasePort's take

Moderate signal
editorial:auto 8d

Version 1.8.230 adds security mitigations by enabling non‑ASCII character escaping in the HTML purifier and sending a Content‑Security‑Policy header for /ajax-html/ endpoints.

Why it matters: Two high‑severity (80) security fixes—Core.EscapeNonASCIICharacters activation and CSP header addition—reduce abuse vectors; operators should deploy this release immediately.

Summary

AI summary

Fixed real‑time notification bugs and added security headers to close two abuse vectors.

Changes in this release

Security High

Enables Core.EscapeNonASCIICharacters in Purifier (Security: GHSA-6w8v-qp43-vg2h)

Enables Core.EscapeNonASCIICharacters in Purifier (Security: GHSA-6w8v-qp43-vg2h)

Source: llm_adapter@2026-07-18

Confidence: high

Security High

Sends CSP header in /ajax-html/ URLs (Security: GHSA-2g42-f97q-973x)

Sends CSP header in /ajax-html/ URLs (Security: GHSA-2g42-f97q-973x)

Source: llm_adapter@2026-07-18

Confidence: high

Feature Low

Adds saving conversation subject when pressing Enter in the subject field

Adds saving conversation subject when pressing Enter in the subject field

Source: llm_adapter@2026-07-18

Confidence: high

Bugfix Medium

Fixes sending notifications to users when a customer replies to a Spam conversation

Fixes sending notifications to users when a customer replies to a Spam conversation

Source: llm_adapter@2026-07-18

Confidence: high

Bugfix Medium

Improves showing bell notifications

Improves showing bell notifications

Source: llm_adapter@2026-07-18

Confidence: high

Bugfix Medium

Fixes real time bell notifications

Fixes real time bell notifications

Source: llm_adapter@2026-07-18

Confidence: high

Bugfix Medium

Fixes separating replies from Outlook

Fixes separating replies from Outlook

Source: llm_adapter@2026-07-18

Confidence: high

Full changelog

Added

  • Save conversation subject when pressing Enter in the subject field (#5492)

Fixed

  • Do not send notifications to users when customer replies to a Spam conversation.
  • Improved showing bell notifications (#5491)
  • Enabled Core.EscapeNonASCIICharacters in Purifier (#5481)
  • Improved remote URL sanitizing (Security: GHSA-6w8v-qp43-vg2h)
  • Send CSP header in /ajax-html/ URLs (Security: GHSA-2g42-f97q-973x)
  • Fixed real time bell notifications (#5499)
  • Fixed separating replies from Outlook (#5504)

Security Fixes

  • dep: GHSA-6w8v-qp43-vg2h — Improved remote URL sanitizing to prevent injection abuse
  • dep: GHSA-2g42-f97q-973x — Send CSP header in `/ajax-html/` URLs to mitigate content‑security risks

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track freescout

Get notified when new releases ship.

Sign up free

About freescout

FreeScout — Free self-hosted help desk & shared mailbox (Zendesk / Help Scout alternative)

All releases →

Related context

Related tools

Earlier breaking changes

  • v1.8.221 Links to attachments uploaded before 2020-03-06 will become unavailable.
  • v1.8.220 Replies to previously received email notifications will not be sent to customers.

Beta — feedback welcome: [email protected]