PT-2025-39901 · Freshrss · Freshrss

Inverle

·

Published

2025-09-29

·

Updated

2025-09-30

·

CVE-2025-54591

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FreshRSS versions 1.26.3 and below
Description FreshRSS, a self-hostable RSS aggregator, discloses information about feeds and tags belonging to default admin users. This is due to missing access controls within the FreshRSS Auth::hasAccess() function, which is utilized by certain tag and feed-related endpoints. Specifically, some FreshRSS controllers lack a defined firstAction() method or manual access checks, leading to unauthorized information exposure. The issue is addressed in version 1.27.0.
Recommendations Update to version 1.27.0 or later.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-54591
GHSA-JF4V-F8P2-8XVQ

Affected Products

Freshrss