PT-2026-61702 · Freescout · Freescout

CVE-2026-53592

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v3.1

4.6

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.223
Description A Prototype Pollution condition exists in the getQueryParam() function within the /public/js/main.js file. This occurs because the application fails to properly sanitize nested URL query keys, allowing an attacker to bypass initial filters that only blocked top-level proto keys. By using nested forms, an attacker can write arbitrary properties into Object.prototype on any page loading the affected script. Prototype Pollution is a vulnerability where an attacker can manipulate the prototype of a base object, potentially leading to unexpected behavior or security bypasses.
Recommendations Update to version 1.8.223.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53592
GHSA-W5FC-8PP3-F755

Affected Products

Freescout