PT-2025-53609 · Freshrss · Freshrss

Hackerman70000

·

Published

2025-12-26

·

Updated

2026-01-01

·

CVE-2025-68932

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreshRSS versions prior to 1.28.0
Description FreshRSS utilizes weak random number generators (mt rand() and uniqid()) for creating remember-me authentication tokens and challenge-response nonces. This allows attackers to predict valid session tokens, potentially leading to account takeover through persistent session hijacking. The remember-me tokens provide permanent authentication and are used for the "keep me logged in" feature.
Recommendations Update to version 1.28.0 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-68932
GHSA-J9WC-GWC6-P786

Affected Products

Freshrss