VulnerabilityAnalyzed
CVE-2025-62166
Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed.
HIGH 7.5EPSS 0.38%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the default user's feed should be viewable if anonymous viewing is enabled, and feeds of other users should be private. This vulnerability is fixed in 1.28.0.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284, CWE-639
- Affected
- freshrss/freshrss
- Source
- security-advisories@github.com
References
- https://github.com/FreshRSS/FreshRSS/commit/60cf5ea297a17db861e73cd65d7b7862bd6bcc24Patch
- https://github.com/FreshRSS/FreshRSS/pull/8165Issue Tracking, Patch
- https://github.com/FreshRSS/FreshRSS/releases/tag/1.28.0Product, Release Notes
- https://github.com/FreshRSS/FreshRSS/security/advisories/GHSA-w743-fg6g-mhwhExploit, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.