FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the default user's feed should be viewable if anonymous viewing is enabled, and feeds of other users should be private. This vulnerability is fixed in 1.28.0.
References
| Link | Resource |
|---|---|
| https://github.com/FreshRSS/FreshRSS/commit/60cf5ea297a17db861e73cd65d7b7862bd6bcc24 | Patch |
| https://github.com/FreshRSS/FreshRSS/pull/8165 | Issue Tracking Patch |
| https://github.com/FreshRSS/FreshRSS/releases/tag/1.28.0 | Product Release Notes |
| https://github.com/FreshRSS/FreshRSS/security/advisories/GHSA-w743-fg6g-mhwh | Exploit Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-03-09 20:16
Updated : 2026-03-13 19:39
NVD link : CVE-2025-62166
Mitre link : CVE-2025-62166
CVE.ORG link : CVE-2025-62166
JSON object : View
Products Affected
freshrss
- freshrss
