PT-2026-61703 · Freescout Help Desk · Freescout

CVE-2026-53593

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous file uploads (Helper::$restricted extensions) is incomplete: it does not cover the .pht extension. The authenticated upload endpoint POST /uploads/upload (SecureController@upload) stores files with their original extension into the web-accessible directory storage/app/public/uploads/ (served at /storage/uploads/). On the standard Apache + libapache2-mod-php deployment, the default handler <FilesMatch ".+.ph(ar|p[3457]?|t|tml)$"> executes .pht, so any authenticated agent can upload a .pht web shell and run arbitrary commands as the web-server user (www-data). This is a direct bypass of the fix for CVE-2025-48471, which added phtml/phar but not pht (nor phtm, phps). Version 1.8.224 contains an updated fix.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53593

Affected Products

Freescout