HIGH
FreshRSS has an IDOR which allows for viewing feeds of any user and leaking tokens
Published Mar 9, 2026
7.5
HIGHCVSS 3.1
EPSS 0.39%
Description
FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the default user's feed should be viewable if anonymous viewing is enabled, and feeds of other users should be private. This vulnerability is fixed in 1.28.0.
Affected products
-
- Version < 1.28.0StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-208442 Advisory
- https://github.com/FreshRSS/FreshRSS/commit/60cf5ea297a17db861e73cd65d7b7862bd6bcc24 x_refsource_MISCPatch
- https://github.com/FreshRSS/FreshRSS/pull/8165 x_refsource_MISCIssue TrackingPatch
- https://github.com/FreshRSS/FreshRSS/releases/tag/1.28.0 x_refsource_MISCProductRelease Notes
- https://github.com/FreshRSS/FreshRSS/security/advisories/GHSA-w743-fg6g-mhwh x_refsource_CONFIRMExploitPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-208442 | Advisory | |
| https://github.com/FreshRSS/FreshRSS/commit/60cf5ea297a17db861e73cd65d7b7862bd6bcc24 | x_refsource_MISCPatch | |
| https://github.com/FreshRSS/FreshRSS/pull/8165 | x_refsource_MISCIssue TrackingPatch | |
| https://github.com/FreshRSS/FreshRSS/releases/tag/1.28.0 | x_refsource_MISCProductRelease Notes | |
| https://github.com/FreshRSS/FreshRSS/security/advisories/GHSA-w743-fg6g-mhwh | x_refsource_CONFIRMExploitPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Mar 9, 2026
Updated Mar 9, 2026
Reserved Oct 7, 2025
Link CVE-2025-62166
CISA Vulnrichment
Updated Mar 9, 2026
ENISA EUVD
EUVD-2025-208442 Assigner GitHub_M
Published Mar 9, 2026
Updated Mar 9, 2026
Exploited since n/a
Link EUVD-2025-208442