CVE-2025-54593: FreshRSS is vulnerable to RCE attacks by authenticated admin
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can execute arbitrary code on the FreshRSS server by modifying the update URL to one they control, and gain code execution after running an update. After successfully executing code, user data including hashed passwords can be exfiltrated, the instance can be defaced when file permissions allow. Malicious code can be inserted into the instance to steal plaintext passwords, among others. This is fixed in version 1.26.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54593?
CVE-2025-54593 has a high severity rating as it allows authenticated administrators to execute arbitrary code on the FreshRSS server.
What versions of FreshRSS are affected by CVE-2025-54593?
CVE-2025-54593 affects FreshRSS versions 1.26.1 and below.
How do I fix CVE-2025-54593?
To fix CVE-2025-54593, upgrade FreshRSS to version 1.26.2 or later.
What are the implications of CVE-2025-54593?
The implications of CVE-2025-54593 include potential unauthorized access and code execution on the FreshRSS server.
Who can exploit CVE-2025-54593?
CVE-2025-54593 can be exploited by authenticated administrator users of FreshRSS.