FreshRSS is vulnerable to RCE attacks by authenticated admin
Published Aug 1, 2025
7.2
HIGHCVSS 3.1
EPSS 0.81%
Description
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can execute arbitrary code on the FreshRSS server by modifying the update URL to one they control, and gain code execution after running an update. After successfully executing code, user data including hashed passwords can be exfiltrated, the instance can be defaced when file permissions allow. Malicious code can be inserted into the instance to steal plaintext passwords, among others. This is fixed in version 1.26.2.
Affected products
-
Affected
- < 1.26.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23380 Advisory
- https://github.com/FreshRSS/FreshRSS/commit/dbdadbb4107878d9233f635c31a88afe45957101 x_refsource_MISCPatch
- https://github.com/FreshRSS/FreshRSS/pull/7477 x_refsource_MISCIssue Tracking
- https://github.com/FreshRSS/FreshRSS/releases/tag/1.26.2 x_refsource_MISCRelease Notes
- https://github.com/FreshRSS/FreshRSS/security/advisories/GHSA-jcww-48g9-wf57 x_refsource_CONFIRMExploitVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23380 | Advisory | |
| https://github.com/FreshRSS/FreshRSS/commit/dbdadbb4107878d9233f635c31a88afe45957101 | x_refsource_MISCPatch | |
| https://github.com/FreshRSS/FreshRSS/pull/7477 | x_refsource_MISCIssue Tracking | |
| https://github.com/FreshRSS/FreshRSS/releases/tag/1.26.2 | x_refsource_MISCRelease Notes | |
| https://github.com/FreshRSS/FreshRSS/security/advisories/GHSA-jcww-48g9-wf57 | x_refsource_CONFIRMExploitVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data