CVE-2025-62166

FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the default user's feed should be viewable if anonymous viewing is enabled, and feeds of other users should be private. This vulnerability is fixed in 1.28.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freshrss:freshrss:*:*:*:*:*:*:*:*

History

13 Mar 2026, 19:39

Type Values Removed Values Added
References () https://github.com/FreshRSS/FreshRSS/commit/60cf5ea297a17db861e73cd65d7b7862bd6bcc24 - () https://github.com/FreshRSS/FreshRSS/commit/60cf5ea297a17db861e73cd65d7b7862bd6bcc24 - Patch
References () https://github.com/FreshRSS/FreshRSS/pull/8165 - () https://github.com/FreshRSS/FreshRSS/pull/8165 - Issue Tracking, Patch
References () https://github.com/FreshRSS/FreshRSS/releases/tag/1.28.0 - () https://github.com/FreshRSS/FreshRSS/releases/tag/1.28.0 - Product, Release Notes
References () https://github.com/FreshRSS/FreshRSS/security/advisories/GHSA-w743-fg6g-mhwh - () https://github.com/FreshRSS/FreshRSS/security/advisories/GHSA-w743-fg6g-mhwh - Exploit, Patch, Vendor Advisory
CPE cpe:2.3:a:freshrss:freshrss:*:*:*:*:*:*:*:*
First Time Freshrss
Freshrss freshrss

11 Mar 2026, 13:53

Type Values Removed Values Added
Summary
  • (es) FreshRSS es un agregador RSS gratuito y autoalojable. Antes de la 1.28.0, un error en la lógica de autenticación relacionado con los tokens de autenticación maestros, esta restricción es eludida. Normalmente, solo la fuente del usuario predeterminado debería ser visible si la visualización anónima está habilitada, y las fuentes de otros usuarios deberían ser privadas. Esta vulnerabilidad está corregida en la 1.28.0.

09 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-09 20:16

Updated : 2026-03-13 19:39


NVD link : CVE-2025-62166

Mitre link : CVE-2025-62166

CVE.ORG link : CVE-2025-62166


JSON object : View

Products Affected

freshrss

  • freshrss
CWE
CWE-284

Improper Access Control

CWE-639

Authorization Bypass Through User-Controlled Key