CVE-2026-107393: FreeScout: Stored HTML Injection in Administrator Alert Emails via Spoofed CF-Connecting-IP Header
FreeScout is a self-hosted help desk and shared mailbox. Prior to 1.8.235, when APPCLOUDFLAREISUSED is enabled, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts and stores the spoofed value in the activity log. LogsMonitor inserts the value into an administrator alert email without HTML escaping, allowing injected HTML to execute when an administrator opens the email. This issue is fixed in version 1.8.235.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeScoutto a version that resolves this vulnerability.Fixed in 1.8.235
Event History
Frequently Asked Questions
Which deployments are exposed?
FreeScout deployments prior to 1.8.235 are affected when APP_CLOUDFLARE_IS_USED is enabled. The issue involves failed-login activity logging and administrator alert emails generated by LogsMonitor.
What does an attacker need to do to exploit this?
An attacker needs network access to submit failed login attempts and must be able to send a spoofed CF-Connecting-IP header. Exploitation also requires an administrator to open the resulting alert email.
Is authentication required for exploitation?
No. The vector is a failed login attempt, and the supplied CVSS vector lists privileges required as none.
How can I remediate the issue?
Upgrade FreeScout to version 1.8.235, which fixes the vulnerability. If upgrading cannot happen immediately, disabling APP_CLOUDFLARE_IS_USED removes the configuration condition described as enabling the vulnerable header handling.
How can I assess whether exploitation may have occurred?
Review failed-login activity records and related administrator alert emails for unexpected HTML or suspicious values in the logged client IP field. The spoofed CF-Connecting-IP value is stored in the activity log and inserted into alert emails.