CVE-2026-48812
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's attachment download
CVSS
7.5
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Jul 20, 2026 · Last modified: Jul 20, 2026 · CWE-287
Not enough EPSS history yet.
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's attachment download route skips token authentication for any attachment whose `token_type` is set to `1` (`TOKEN_TYPE_LEGACY`). Because this route is unauthenticated and the file path is deterministic, an unauthenticated remote attacker can download any attachment that was created by an older version of FreeScout without possessing a valid token or session. Version 1.8.221 contains a fix.
- github.comhttps://github.com/freescout-help-desk/freescout/commit/215241ee2eb73eaa3b47e392599c7dc1b427dc7e
- github.comhttps://github.com/freescout-help-desk/freescout/security/advisories/GHSA-wg74-ww4w-2qpc
- github.comhttps://github.com/freescout-help-desk/freescout/security/advisories/GHSA-wg74-ww4w-2qpc