PT-2025-39904 · Freshrss · Freshrss

Inverle

·

Published

2025-09-29

·

Updated

2025-09-29

·

CVE-2025-54875

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreshRSS versions 1.16.0 through 1.26.3
Description FreshRSS is a free, self-hostable RSS aggregator. An unprivileged attacker can create a new administrator user when registration is enabled. This is achieved through manipulation of a hidden field, new user is admin, used on the user management admin page. The field allows an attacker to set the new user is admin parameter to '1' during registration, granting them administrative privileges.
Recommendations Update to version 1.27.0 or later.

Exploit

Fix

LPE

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-54875
GHSA-H625-GHR3-JPPQ

Affected Products

Freshrss