Skip to content

freescout

v1.8.226 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 29d Communication & Email
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

customer-support help-desk helpdesk helpdesk-ticketing helpscout laravel
+8 more
osticket-alternative php shared-mailboxes support ticketing ticketing-system zendesk zendesk-alternative

Affected surfaces

auth rbac

Summary

AI summary

Fixed multiple bugs including pagination loss, JSON decode errors, access checks, and URL linkifying.

Full changelog

Fixed

  • Paginate by SEARCH count so the newest emails are never dropped (#546)
  • Fixed json_decode() error in User::hasManageMailboxPermission() (#5465)
  • Fixed Error 500 in ConversationsController::view when a user has no Mine folder (#5466)
  • Fixed "Could not scan for classes" error (#5469)
  • Escape channel name in LIKE query in PolycastServiceProvider.php (Security: GHSA-gh3r-jh6q-wrvj)
  • Fixed access check in realtime Polycast events (Security: GHSA-gh3r-jh6q-wrvj)
  • Improved RealtimeConvNewThread event access check (Security: GHSA-w668-wq26-6c94)
  • Prevent sending blank email when Summernote leaves empty HTML tags (#5478)
  • Check access permissions when searching conversations by number (Security: GHSA-wqq7-4q7m-273v)
  • Fixed: customer Waiting Since shows time of the last customer message instead of the first (#5475)
  • Send reply on CMD+Enter on Mac (#5476)
  • On fetching preserve top-posted reply content before nested <html> block (Yahoo/Android) (#5409)
  • Allow to create users without the last name (#4184)
  • Fixed linkifying URLs ending with > symbol (#5423)
  • Fixed @fwd feature for Outlook emails (#5480)

Security Fixes

  • GHSA-gh3r-jh6q-wrvj — fixed channel name escaping in LIKE query and realtime Polycast events access check
  • GHSA-w668-wq26-6c94 — improved RealtimeConvNewThread event access check
  • GHSA-wqq7-4q7m-273v — added conversation number search permission check

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track freescout

Get notified when new releases ship.

Sign up free

About freescout

FreeScout — Free self-hosted help desk & shared mailbox (Zendesk / Help Scout alternative)

All releases →

Related context

Related tools

Earlier breaking changes

  • v1.8.221 Links to attachments uploaded before 2020-03-06 will become unavailable.
  • v1.8.220 Replies to previously received email notifications will not be sent to customers.

Beta — feedback welcome: [email protected]