Skip to content

freescout

v1.8.224 Security

This release includes 4 security fixes for security teams reviewing exposed deployments.

Published 1mo Communication & Email
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 4 known CVEs

Topics

customer-support help-desk helpdesk helpdesk-ticketing helpscout laravel
+8 more
osticket-alternative php shared-mailboxes support ticketing ticketing-system zendesk zendesk-alternative

Affected surfaces

auth deps

ReleasePort's take

Moderate signal
editorial:auto 1mo

Version 1.8.224 of FreeScout introduces several security enhancements: throttling file‑upload routes, fixing empty invite_hash during user setup, improving log‑file download logic, and restricting .pht uploads.

Why it matters: All four fixes have a severity score of 90; addressing them prevents abuse of upload endpoints, ensures reliable user onboarding, safeguards log retrieval, and blocks potentially malicious .pht files. Operators should apply the update promptly to mitigate these high‑severity risks.

Summary

AI summary

Multiple security fixes including throttling file uploads, fixing invite_hash issues, and enforcing CSP in browsers.

Changes in this release

Security Critical

Adds throttling to file upload routes (GHSA-ph4f-2jhx-q76w)

Adds throttling to file upload routes (GHSA-ph4f-2jhx-q76w)

Source: llm_adapter@2026-06-06

Confidence: high

Security Critical

Fixes empty invite_hash during user setup (GHSA-jqj5-r72v-v29g)

Fixes empty invite_hash during user setup (GHSA-jqj5-r72v-v29g)

Source: llm_adapter@2026-06-06

Confidence: high

Security Critical

Improves downloading log files logic (GHSA-858x-8f77-9vc5)

Improves downloading log files logic (GHSA-858x-8f77-9vc5)

Source: llm_adapter@2026-06-06

Confidence: high

Security Critical

Restricts upload of .pht files (GHSA-27vp-fpg8-j8wv)

Restricts upload of .pht files (GHSA-27vp-fpg8-j8wv)

Source: llm_adapter@2026-06-06

Confidence: high

Feature Medium

Enables browser check; blocks browsers without CSP support

Enables browser check; blocks browsers without CSP support

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Medium

Improves sanitizing of customer Websites field

Improves sanitizing of customer Websites field

Source: llm_adapter@2026-06-06

Confidence: high

Full changelog

Fixed

  • Added throttling to file upload routes (Security: GHSA-ph4f-2jhx-q76w)
  • Fixed user-setup empty invite_hash issue (Security: GHSA-jqj5-r72v-v29g)
  • Improved downloading log files logic (Security: GHSA-858x-8f77-9vc5)
  • Restricted .pht files upload (Security: GHSA-27vp-fpg8-j8wv)
  • Improved sanitizing customer Websites field.
  • Enabled browser check - now it will be impossible to access FreeScout instance from a browser which does not support CSP.

Security Fixes

  • GHSA-ph4f-2jhx-q76w — Added throttling to file upload routes
  • GHSA-jqj5-r72v-v29g — Fixed user-setup empty `invite_hash` issue
  • GHSA-858x-8f77-9vc5 — Improved downloading log files logic (Security)
  • GHSA-27vp-fpg8-j8wv — Restricted `.pht` file uploads

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track freescout

Get notified when new releases ship.

Sign up free

About freescout

FreeScout — Free self-hosted help desk & shared mailbox (Zendesk / Help Scout alternative)

All releases →

Related context

Related tools

Earlier breaking changes

  • v1.8.221 Links to attachments uploaded before 2020-03-06 will become unavailable.
  • v1.8.220 Replies to previously received email notifications will not be sent to customers.

Beta — feedback welcome: [email protected]