---
id: CVE-2025-68927
title: Libredesk is a self-hosted customer support desk
summary: >-
  Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta,
  LibreDesk is vulnerable to stored HTML injection in the contact notes feature.
  When adding notes via POST /api/v1/contacts/{id}/notes, the backend
  automatical…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: libredesk
product: libredesk
affected:
  - libredesk < 0.8.6
patched:
  - libredesk 0.8.6
published: '2025-12-27'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:10:00.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-68927'
references:
  - url: >-
      https://github.com/abhinavxd/libredesk/commit/270347849943ac6a43e9fd6ebdc99c71841900eb
    label: security-advisories@github.com
  - url: >-
      https://github.com/abhinavxd/libredesk/security/advisories/GHSA-wh6m-h6f4-rjf4
    label: security-advisories@github.com
  - url: >-
      https://github.com/abhinavxd/libredesk/security/advisories/GHSA-wh6m-h6f4-rjf4
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00231
epssPercentile: 0.12649
ingestedAt: '2026-10-05T19:30:59.939Z'
---

## Overview

Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML injection in the contact notes feature. When adding notes via POST /api/v1/contacts/{id}/notes, the backend automatically wraps user input in <p> tags. However, by intercepting the request and removing the <p> tag, an attacker can inject arbitrary HTML elements such as forms and images, which are then stored and rendered without proper sanitization. This can lead to phishing, CSRF-style forced actions, and UI redress attacks. This issue has been patched in version 0.8.6-beta.

## Affected

- `libredesk < 0.8.6`

## Remediation

Upgrade past the affected range:

- `libredesk 0.8.6`
