CVE-2026-41193: FreeScout has Zip Slip path traversal in module installation that allows arbitrary file write leading to RCE
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation feature extracts ZIP archives without validating file paths, allowing an authenticated admin to write files arbitrarily on the server filesystem via a specially crafted ZIP. Version 1.8.215 fixes the vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41193?
CVE-2026-41193 is a critical vulnerability that allows arbitrary file writes leading to remote code execution.
How do I fix CVE-2026-41193?
To fix CVE-2026-41193, you should upgrade FreeScout to version 1.8.215 or later.
What component of FreeScout is affected by CVE-2026-41193?
CVE-2026-41193 affects the module installation feature of FreeScout.
What is the root cause of CVE-2026-41193?
The root cause of CVE-2026-41193 is the failure to validate file paths when extracting ZIP archives.
Can CVE-2026-41193 lead to a full system compromise?
Yes, CVE-2026-41193 can lead to a full system compromise due to remote code execution capabilities.