Your RSA-2048 keys break in 2030. Find every one of them before attackers do.

CVE-2026-53593

HIGH

FreeScout Vulnerable to Authenticated Remote Code Execution via incomplete upload extension denylist (.pht) — bypass of CVE-2025-48471

Also known asGHSA-27vp-fpg8-j8wv
Published
Jul 20, 2026
Updated
Jul 22, 2026
Affected
0 pkgs
Patched
None yet
Exploits
None indexed

Description

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous file uploads (Helper::$restricted_extensions) is incomplete: it does not cover the .pht extension. The authenticated upload endpoint POST /uploads/upload (SecureController@upload) stores files with their original extension into the web-accessible directory storage/app/public/uploads/ (served at /storage/uploads/). On the standard Apache + libapache2-mod-php deployment, the default handler <FilesMatch ".+\.ph(ar|p[3457]?|t|tml)$"> executes .pht, so any authenticated agent can upload a .pht web shell and run arbitrary commands as the web-server user (www-data). This is a direct bypass of the fix for CVE-2025-48471, which added phtml/phar but not pht (nor phtm, phps). Version 1.8.224 contains an updated fix.

Detection & mitigation playbook

Vulnerability
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for the affected component. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match.

  2. Remediation status

    No patched version of the affected component has shipped for CVE-2026-53593 yet. Where your build allows, override or pin the dependency away from the vulnerable range, and apply any maintainer-recommended mitigation.

  3. Mitigate without a patch

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 pinpoints whether CVE-2026-53593 is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed.

Tailored to CVE-2026-53593. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous file uploads (`Helper::$restricted_extensions`) is incomplete: it does not cover the `.pht` extension. The authenticated upload endpoint `POST /uploads/upload` (`SecureController@upload`) stores files with their original extension into the web-accessible directory `storage/app/public/uploads/` (served at `/storage/uploads/`). On the standard Apache + `libapache2-mod-php` deployment, the default handler `<FilesMatch ".+\.ph(ar|p[3457]?|t|tml)$">` e
O3 Security · Impact-Aware SCA

Is CVE-2026-53593 in your dependencies?

O3 detects CVE-2026-53593 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.

CVE-2026-53593: high severity vulnerability (CVSS 8.8) | O3 Security