CVE-2026-41905Disclosure

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::sanitizeRemoteUrl() in app/Misc/Helper.php follows HTTP redirects via curlGetLastRedirectedUrl() but then re-validates the original URL instead of the final redirect destination. An attacker who can supply any URL that passes the initial host check can redirect FreeScout to internal HTTP services (cloud metadata, internal APIs, RFC1918 ranges) that would normally be blocked. This issue has been patched in version 1.8.217.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-07); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-07: 3Mentions · 2026-05-08: 1Technical Details · 2026-05-07: 2Technical Details · 2026-05-08: 105-0705-08
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-073
Disclosure1General2
2026-05-081
Disclosure1
Full discourse4 posts
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-41905 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::sa… CVSS 7.7 Full analysis → https://sec.kaitan.id/cves/CVE-2026-41905 #HP #CyberSecurity #InfoSec

    Post summary

    A high‑severity vulnerability (CVE‑2026‑41905) affecting FreeScout versions before 1.8.217 has been identified, with a CVSS score of 7.7, and is detailed in an online analysis page.

    0001048
    515 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41905 Server-Side Request Forgery via HTTP Redirect in FreeScout Before 1.8.217 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41905

    Post summary

    The text announces CVE‑2026‑41905, noting it as a Server‑Side Request Forgery issue in FreeScout versions prior to 1.8.217.

    0000054
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-41905 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::sanitizeRemoteUrl() in app/Misc/Helper.php follow… https://www.cve.org/CVERecord?id=CVE-2026-41905 ----- Traducción: CVE-2026-41905 Fre… http://infoflow.cloud`

    Post summary

    The message merely announces CVE‑2026‑41905, links to the CVE record, and notes the affected Laravel function without providing exploit, patch, or active‑use details.

    0000037
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-41905 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::sanitizeRemoteUrl() in app/Misc/Helper.php follow… https://www.cve.org/CVERecord?id=CVE-2026-41905

    Post summary

    A concise note referencing CVE-2026‑41905, offering a link to its CVE record and a brief code path, without any exploitation, patch, or in‑depth technical details.

    00000175
    57.4K followersView on X

Explore more