FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, an attacker can gain additional information about the server by checking if certain directories exist. An attacker can, for example, check if older PHP versions are installed or if certain software is installed on the server and potentially use that information to further attack the server. Version 1.26.2 contains a patch for the issue.
History

Tue, 10 Jun 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Freshrss
Freshrss freshrss
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:freshrss:freshrss:*:*:*:*:*:*:*:*
Vendors & Products Freshrss
Freshrss freshrss
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 04 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Jun 2025 19:45:00 +0000

Type Values Removed Values Added
Description FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, an attacker can gain additional information about the server by checking if certain directories exist. An attacker can, for example, check if older PHP versions are installed or if certain software is installed on the server and potentially use that information to further attack the server. Version 1.26.2 contains a patch for the issue.
Title FreshRSS vulnerable to directory enumeration via ext.php
Weaknesses CWE-201
References
Metrics cvssV4_0

{'score': 5.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-04T19:35:55.749Z

Updated: 2025-06-04T20:07:03.452Z

Reserved: 2025-03-26T15:04:52.627Z

Link: CVE-2025-31134

cve-icon Vulnrichment

Updated: 2025-06-04T20:06:54.739Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-04T20:15:22.657

Modified: 2025-06-10T15:08:24.457

Link: CVE-2025-31134

cve-icon Redhat

No data.