This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+8 more
Affected surfaces
ReleasePort's take
Moderate signalVersion 1.8.230 adds security mitigations by enabling non‑ASCII character escaping in the HTML purifier and sending a Content‑Security‑Policy header for /ajax-html/ endpoints.
Why it matters: Two high‑severity (80) security fixes—Core.EscapeNonASCIICharacters activation and CSP header addition—reduce abuse vectors; operators should deploy this release immediately.
Summary
AI summaryFixed real‑time notification bugs and added security headers to close two abuse vectors.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Enables Core.EscapeNonASCIICharacters in Purifier (Security: GHSA-6w8v-qp43-vg2h) Enables Core.EscapeNonASCIICharacters in Purifier (Security: GHSA-6w8v-qp43-vg2h) Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Security | High |
Sends CSP header in /ajax-html/ URLs (Security: GHSA-2g42-f97q-973x) Sends CSP header in /ajax-html/ URLs (Security: GHSA-2g42-f97q-973x) Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Low |
Adds saving conversation subject when pressing Enter in the subject field Adds saving conversation subject when pressing Enter in the subject field Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Fixes sending notifications to users when a customer replies to a Spam conversation Fixes sending notifications to users when a customer replies to a Spam conversation Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Improves showing bell notifications Improves showing bell notifications Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Fixes real time bell notifications Fixes real time bell notifications Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Fixes separating replies from Outlook Fixes separating replies from Outlook Source: llm_adapter@2026-07-18 Confidence: high |
— |
Full changelog
Added
- Save conversation subject when pressing Enter in the subject field (#5492)
Fixed
- Do not send notifications to users when customer replies to a Spam conversation.
- Improved showing bell notifications (#5491)
- Enabled
Core.EscapeNonASCIICharactersin Purifier (#5481) - Improved remote URL sanitizing (Security: GHSA-6w8v-qp43-vg2h)
- Send CSP header in
/ajax-html/URLs (Security: GHSA-2g42-f97q-973x) - Fixed real time bell notifications (#5499)
- Fixed separating replies from Outlook (#5504)
Security Fixes
- dep: GHSA-6w8v-qp43-vg2h — Improved remote URL sanitizing to prevent injection abuse
- dep: GHSA-2g42-f97q-973x — Send CSP header in `/ajax-html/` URLs to mitigate content‑security risks
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About freescout
FreeScout — Free self-hosted help desk & shared mailbox (Zendesk / Help Scout alternative)
Beta — feedback welcome: [email protected]