VulnerabilityAnalyzed
CVE-2025-59949
Versions prior to 1.27.1 have a logout cross-site request forgery vulnerability that can lead to denial of service via <track src>.
MEDIUM 6.5EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
FreshRSS is a free, self-hostable RSS aggregator. Versions prior to 1.27.1 have a logout cross-site request forgery vulnerability that can lead to denial of service via <track src>. Version 1.27.1 patches the issue.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 0.43% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- freshrss/freshrss
- Source
- security-advisories@github.com
References
- https://github.com/FreshRSS/FreshRSS/pull/7958Issue Tracking, Patch
- https://github.com/FreshRSS/FreshRSS/pull/7997Issue Tracking, Patch
- https://github.com/FreshRSS/FreshRSS/pull/7999Issue Tracking
- https://github.com/FreshRSS/FreshRSS/security/advisories/GHSA-w7f5-8vf9-f966Exploit, Vendor Advisory
- https://github.com/FreshRSS/FreshRSS/security/advisories/GHSA-w7f5-8vf9-f966Exploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.