CVE-2026-53592: FreeScout vulnerable to prototype pollution in getQueryParam
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in the getQueryParam function /public/js/main.js and was addressed in version 1.8.139 by blocking URL query keys matching the pattern proto. However, this mitigation is incomplete: it only filters top-level proto keys and fails to sanitize nested forms such as b[proto][polluted]=PWNED. As a result, an attacker-controlled URL query string can still write into Object.prototype on any page that loads main.js. Version 1.8.223 contains a updated fix.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeScoutto a version that resolves this vulnerability.Fixed in 1.8.223
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53592?
The severity of CVE-2026-53592 is medium with a score of 4.6.
How do I fix CVE-2026-53592?
To fix CVE-2026-53592, update FreeScout to version 1.8.139 or later.
What kind of vulnerability is CVE-2026-53592?
CVE-2026-53592 is a prototype pollution vulnerability in the `getQueryParam` function.
What impact does CVE-2026-53592 have on FreeScout?
CVE-2026-53592 can lead to potential manipulation of the application state by an attacker due to the vulnerability.
In which component of FreeScout does CVE-2026-53592 occur?
CVE-2026-53592 occurs in the `/public/js/main.js` file within the FreeScout application.