{"api_version":"1","generated_at":"2026-10-09T00:39:55+00:00","cve":"CVE-2026-107393","urls":{"html":"https://cve.report/CVE-2026-107393","api":"https://cve.report/api/cve/CVE-2026-107393.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-107393","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-107393"},"summary":{"title":"FreeScout: Stored HTML Injection in Administrator Alert Emails via Spoofed CF-Connecting-IP Header","description":"FreeScout is a self-hosted help desk and shared mailbox. Prior to 1.8.235, when APP_CLOUDFLARE_IS_USED is enabled, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts and stores the spoofed value in the activity log. LogsMonitor inserts the value into an administrator alert email without HTML escaping, allowing injected HTML to execute when an administrator opens the email. This issue is fixed in version 1.8.235.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-10-08 20:17:33","updated_at":"2026-10-08 21:33:42"},"problem_types":["CWE-79","CWE-116","CWE-79 CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","CWE-116 CWE-116: Improper Encoding or Escaping of Output"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"6.1","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"6.1","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://github.com/freescout-help-desk/freescout/releases/tag/1.8.235","name":"https://github.com/freescout-help-desk/freescout/releases/tag/1.8.235","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-9cm3-qvj2-8hg4","name":"https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-9cm3-qvj2-8hg4","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/freescout-help-desk/freescout/commit/0f41f5cabb581de156ec8eb344ff6c0e6e0cc66a","name":"https://github.com/freescout-help-desk/freescout/commit/0f41f5cabb581de156ec8eb344ff6c0e6e0cc66a","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-107393","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107393","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"freescout-help-desk","product":"freescout","version":"affected < 1.8.235","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"product":"freescout","vendor":"freescout-help-desk","versions":[{"status":"affected","version":"< 1.8.235"}]}],"descriptions":[{"lang":"en","value":"FreeScout is a self-hosted help desk and shared mailbox. Prior to 1.8.235, when APP_CLOUDFLARE_IS_USED is enabled, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts and stores the spoofed value in the activity log. LogsMonitor inserts the value into an administrator alert email without HTML escaping, allowing injected HTML to execute when an administrator opens the email. This issue is fixed in version 1.8.235."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-116","description":"CWE-116: Improper Encoding or Escaping of Output","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-08T19:52:23.040Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-9cm3-qvj2-8hg4","tags":["x_refsource_CONFIRM"],"url":"https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-9cm3-qvj2-8hg4"},{"name":"https://github.com/freescout-help-desk/freescout/commit/0f41f5cabb581de156ec8eb344ff6c0e6e0cc66a","tags":["x_refsource_MISC"],"url":"https://github.com/freescout-help-desk/freescout/commit/0f41f5cabb581de156ec8eb344ff6c0e6e0cc66a"},{"name":"https://github.com/freescout-help-desk/freescout/releases/tag/1.8.235","tags":["x_refsource_MISC"],"url":"https://github.com/freescout-help-desk/freescout/releases/tag/1.8.235"}],"source":{"advisory":"GHSA-9cm3-qvj2-8hg4","discovery":"UNKNOWN"},"title":"FreeScout: Stored HTML Injection in Administrator Alert Emails via Spoofed CF-Connecting-IP Header"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-107393","datePublished":"2026-10-08T19:52:23.040Z","dateReserved":"2026-10-07T21:07:54.989Z","dateUpdated":"2026-10-08T19:52:23.040Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-08 20:17:33","lastModifiedDate":"2026-10-08 21:33:42","problem_types":["CWE-79","CWE-116","CWE-79 CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","CWE-116 CWE-116: Improper Encoding or Escaping of Output"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"107393","Ordinal":"1","Title":"FreeScout: Stored HTML Injection in Administrator Alert Emails v","CVE":"CVE-2026-107393","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"107393","Ordinal":"1","NoteData":"FreeScout is a self-hosted help desk and shared mailbox. Prior to 1.8.235, when APP_CLOUDFLARE_IS_USED is enabled, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts and stores the spoofed value in the activity log. LogsMonitor inserts the value into an administrator alert email without HTML escaping, allowing injected HTML to execute when an administrator opens the email. This issue is fixed in version 1.8.235.","Type":"Description","Title":"FreeScout: Stored HTML Injection in Administrator Alert Emails v"}]}}}