FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout version (http://localhost:8080/system/status) allows an attacker to inject an arbitrary domain into generated absolute URLs. This leads to External Resource Loading and Open Redirect behavior. When the application constructs links and assets using the unvalidated Host header, user requests can be redirected to attacker-controlled domains and external resources may be loaded from malicious servers. This issue has been patched in version 1.8.211.
References
Configurations
History
01 Apr 2026, 19:49
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:* | |
| First Time |
Freescout
Freescout freescout |
|
| References | () https://github.com/freescout-help-desk/freescout/commit/889d75c8e3c15e6a7ddb6a4d4f65cc0379c29213 - Patch | |
| References | () https://github.com/freescout-help-desk/freescout/releases/tag/1.8.211 - Release Notes | |
| References | () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-822g-7rw5-53xj - Exploit, Vendor Advisory |
01 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-822g-7rw5-53xj - |
31 Mar 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-31 22:16
Updated : 2026-04-01 19:49
NVD link : CVE-2026-34442
Mitre link : CVE-2026-34442
CVE.ORG link : CVE-2026-34442
JSON object : View
Products Affected
freescout
- freescout
