FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the default user's feed should be viewable if anonymous viewing is enabled, and feeds of other users should be private. This vulnerability is fixed in 1.28.0.
References
| Link | Resource |
|---|---|
| https://github.com/FreshRSS/FreshRSS/commit/60cf5ea297a17db861e73cd65d7b7862bd6bcc24 | Patch |
| https://github.com/FreshRSS/FreshRSS/pull/8165 | Issue Tracking Patch |
| https://github.com/FreshRSS/FreshRSS/releases/tag/1.28.0 | Product Release Notes |
| https://github.com/FreshRSS/FreshRSS/security/advisories/GHSA-w743-fg6g-mhwh | Exploit Patch Vendor Advisory |
Configurations
History
13 Mar 2026, 19:39
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/FreshRSS/FreshRSS/commit/60cf5ea297a17db861e73cd65d7b7862bd6bcc24 - Patch | |
| References | () https://github.com/FreshRSS/FreshRSS/pull/8165 - Issue Tracking, Patch | |
| References | () https://github.com/FreshRSS/FreshRSS/releases/tag/1.28.0 - Product, Release Notes | |
| References | () https://github.com/FreshRSS/FreshRSS/security/advisories/GHSA-w743-fg6g-mhwh - Exploit, Patch, Vendor Advisory | |
| CPE | cpe:2.3:a:freshrss:freshrss:*:*:*:*:*:*:*:* | |
| First Time |
Freshrss
Freshrss freshrss |
11 Mar 2026, 13:53
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
09 Mar 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-09 20:16
Updated : 2026-03-13 19:39
NVD link : CVE-2025-62166
Mitre link : CVE-2025-62166
CVE.ORG link : CVE-2025-62166
JSON object : View
Products Affected
freshrss
- freshrss
