Report: CVE-2026-32753 - FreeScout: Stored XSS through SVG file upload with filter bypass

Report: CVE-2026-32753 - FreeScout: Stored XSS through SVG file upload with filter bypass

CVE ID :CVE-2026-32753 Published : March 19, 2026, 9:26 p.m. | 19 minutes ago Description :FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, bypasses of the attachment view logic and SVG sanitizer make it possible to upload and render an SVG that runs malicious JavaScript. An extension of .png with content type of image/svg+xml is allowed, and a fallback mechanism on invalid XML leads to unsafe sanitization. The application restricts which uploaded files are rendered inline: only files considered

CVE Details

Published
March 19, 2026
Affected Product: PHP