PT-2025-23856 · Freshrss · Freshrss
Inverle
·
Published
2025-06-04
·
Updated
2025-06-04
·
CVE-2025-46341
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FreshRSS versions prior to 1.26.2
Description
FreshRSS is a self-hosted RSS feed aggregator. When the server is using HTTP auth via reverse proxy, it's possible to impersonate any user either via the
Remote-User header or the X-WebAuth-User header by making specially crafted requests via the add feed functionality and obtaining the CSRF token via XPath scraping. The attacker has to know the IP address of the proxied FreshRSS instance and the admin's username, while also having an account on the instance. This can lead to unauthorized access to internal services and potentially privilege escalation, although users that have setup OIDC are not affected by privilege escalation.Recommendations
For versions prior to 1.26.2, update to version 1.26.2 to resolve the issue. As a temporary workaround, consider restricting access to the add feed functionality and limiting the use of HTTP auth via reverse proxy until the patch is applied. Additionally, restrict the
Remote-User and X-WebAuth-User headers to prevent header manipulation.Exploit
Fix
LPE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freshrss