CVE-2026-107393
Awaiting Analysis Awaiting Analysis - Queue

Stored XSS in FreeScout Email Alerts via Spoofed CF-Connecting-IP Header

Vulnerability report for CVE-2026-107393, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

FreeScout is a self-hosted help desk and shared mailbox. Prior to 1.8.235, when APP_CLOUDFLARE_IS_USED is enabled, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts and stores the spoofed value in the activity log. LogsMonitor inserts the value into an administrator alert email without HTML escaping, allowing injected HTML to execute when an administrator opens the email. This issue is fixed in version 1.8.235.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
freescout-help-desk freescout < 1.8.235

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-116 The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in FreeScout versions prior to 1.8.235. When Cloudflare is used, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts. Attackers can spoof this header with malicious HTML or JavaScript code, which gets stored in the activity log. When LogsMonitor generates an alert email, it inserts the log value without HTML escaping, allowing the injected code to execute when an administrator opens the email.

The vulnerability occurs because the application does not validate the CF-Connecting-IP header and fails to escape log data in email alerts.

Detection Guidance

Check FreeScout logs for suspicious activity entries containing HTML or JavaScript code in the CF-Connecting-IP field. Review email alert templates for unescaped log variables. Verify if APP_CLOUDFLARE_IS_USED is enabled in the .env file.

Impact Analysis

An attacker could exploit this to execute arbitrary JavaScript in the context of an administrator's browser session. This may lead to session hijacking, phishing attacks, or malicious redirects. Attackers could steal sensitive data, such as session cookies or credentials, or perform actions on behalf of the administrator.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements. If exploited, it may result in data breaches, unauthorized disclosure of personal or health information, and non-compliance with regulatory standards.

Mitigation Strategies

Upgrade FreeScout to version 1.8.235 or later. If unable to upgrade, set APP_CLOUDFLARE_IS_USED=false in the .env file. Ensure input validation for CF-Connecting-IP headers and escape log outputs in email templates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107393. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart