Back

HIGH

FreshRSS has an IDOR which allows for viewing feeds of any user and leaking tokens

Published Mar 9, 2026

Description

FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the default user's feed should be viewable if anonymous viewing is enabled, and feeds of other users should be private. This vulnerability is fixed in 1.28.0.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Mar 9, 2026
Updated Mar 9, 2026
Reserved Oct 7, 2025
CISA Vulnrichment
Updated Mar 9, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Mar 9, 2026
Updated Mar 9, 2026
Exploited since n/a
EUVD-2025-208442