PT-2025-39903 · Freshrss · Freshrss

Baskar18

·

Published

2025-09-29

·

Updated

2025-09-29

·

CVE-2025-54592

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreshRSS versions 1.26.3 and below
Description FreshRSS does not properly end a user session when they log out. The session cookie remains active and can be reused by an attacker to start a new session, potentially leading to session hijacking and fixation.
Recommendations Update to version 1.27.0 or later.

Exploit

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2025-54592
GHSA-42V4-65F8-5WGR

Affected Products

Freshrss