PT-2026-34040 · Freescout · Freescout

Published

2026-04-21

·

Updated

2026-04-22

·

CVE-2026-41193

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.215
Description The module installation feature extracts ZIP archives without validating file paths. This allows an authenticated administrator to write files arbitrarily on the server filesystem by using a specially crafted ZIP archive, a technique known as Zip Slip (a form of directory traversal where files are extracted outside the intended destination folder).
Recommendations Update to version 1.8.215.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-41193

Affected Products

Freescout