CVE-2025-62166

FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the default user's feed should be viewable if anonymous viewing is enabled, and feeds of other users should be private. This vulnerability is fixed in 1.28.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freshrss:freshrss:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-09 20:16

Updated : 2026-03-13 19:39


NVD link : CVE-2025-62166

Mitre link : CVE-2025-62166

CVE.ORG link : CVE-2025-62166


JSON object : View

Products Affected

freshrss

  • freshrss
CWE
CWE-284

Improper Access Control

CWE-639

Authorization Bypass Through User-Controlled Key