CVE-2025-48880: FreeScout has Race Condition When Deleting Users
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, when an administrative account is a deleting a user, there is the the possibility of a race condition occurring. This issue has been patched in version 1.8.181.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48880?
CVE-2025-48880 has been classified as a moderate severity vulnerability due to the potential race condition during user deletion.
How do I fix CVE-2025-48880?
To fix CVE-2025-48880, upgrade your FreeScout installation to version 1.8.181 or later.
Who is affected by CVE-2025-48880?
CVE-2025-48880 affects installations of FreeScout prior to version 1.8.181.
What causes CVE-2025-48880?
CVE-2025-48880 is caused by a race condition that occurs when an administrative account attempts to delete a user.
Is CVE-2025-48880 being actively exploited?
There is currently no known active exploitation of CVE-2025-48880, but it is advisable to apply the patch to mitigate risks.