ZeroHour

CVE-2025-62166

PoC
CVSS 3.1
7.5 high
EPSS
<1%p31
Published
()
Modified
Description

FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the default user's feed should be viewable if anonymous viewing is enabled, and feeds of other users should be private. This vulnerability is fixed in 1.28.0.

Vendors
freshrss
Products
freshrss
Weakness
CWE-284, CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.