CVE Explorer
CVE-2026-32753
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, bypasses of the attachment view logic and SVG sanitizer make it possible to upload and render an SVG that runs malicious JavaScript. An extension of .png with content type of image/svg+xml is allowed, and a fallback mechanism on invalid XML leads to unsafe sanitization. The application restricts which uploaded files are rendered inline: only files considered "safe" are displayed in t
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"freescout","vendor":"freescout-help-desk","versions":[{"status":"affected","version":"< 1.8.209"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c387ad55e659dec7dec11b8f0a89c30c1acafb8dde76d367c26ac43240843997 · sha256:b47ec4bba34fdb0c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.5,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:c387ad55e659dec7dec11b8f0a89c30c1acafb8dde76d367c26ac43240843997 · sha256:b47ec4bba34fdb0c… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-80","description":"CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c387ad55e659dec7dec11b8f0a89c30c1acafb8dde76d367c26ac43240843997 · sha256:b47ec4bba34fdb0c… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/freescout-help-desk/freescout/commit/cb8618845704aef8f5e4a494c7f605e7bd9fdaeb","tags":["x_refsource_MISC"],"url":"https://github.com/freescout-help-desk/freescout/commit/cb8618845704aef8f5e4a494c7f605e7bd9fdaeb"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c387ad55e659dec7dec11b8f0a89c30c1acafb8dde76d367c26ac43240843997 · sha256:b47ec4bba34fdb0c… · /containers/cna/references/1
{"name":"https://github.com/freescout-help-desk/freescout/releases/tag/1.8.209","tags":["x_refsource_MISC"],"url":"https://github.com/freescout-help-desk/freescout/releases/tag/1.8.209"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c387ad55e659dec7dec11b8f0a89c30c1acafb8dde76d367c26ac43240843997 · sha256:b47ec4bba34fdb0c… · /containers/cna/references/2
{"name":"https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-cvr8-cw5c-5pfw","tags":["x_refsource_CONFIRM"],"url":"https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-cvr8-cw5c-5pfw"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c387ad55e659dec7dec11b8f0a89c30c1acafb8dde76d367c26ac43240843997 · sha256:b47ec4bba34fdb0c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.