PT-2025-23846 · Freshrss · Freshrss

Inverle

·

Published

2025-06-04

·

Updated

2025-06-05

·

CVE-2025-31134

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FreshRSS versions prior to 1.26.2
Description FreshRSS is a self-hosted RSS feed aggregator. An attacker can gain additional information about the server by checking if certain directories exist, potentially discovering older PHP versions or installed software. This information could be used to further attack the server.
Recommendations For versions prior to 1.26.2, update to version 1.26.2 to resolve the issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-31134
GHSA-JJM2-4HF7-9X65

Affected Products

Freshrss