PT-2026-38550 · Freescout · Freescout

Whatisproblem

·

Published

2026-05-07

·

Updated

2026-05-08

·

CVE-2026-41905

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.217
Description The sanitizeRemoteUrl() function in app/Misc/Helper.php follows HTTP redirects via curlGetLastRedirectedUrl() but re-validates the original URL instead of the final destination. This allows an attacker to provide a URL that passes the initial host check to redirect the application to internal HTTP services, such as cloud metadata, internal APIs, or RFC1918 ranges, which are typically blocked.
Recommendations Update to version 1.8.217.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41905

Affected Products

Freescout