CVE-2025-54875: FreshRSS: Unauthorized creation of admin user when registration is enabled
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.16.0 and above through 1.26.3, an unprivileged attacker can create a new admin user when registration is enabled through the use of a hidden field used only in the user management admin page, newuserisadmin. This is fixed in version 1.27.0.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54875?
CVE-2025-54875 is rated as a critical vulnerability due to its ability to allow unprivileged attackers to create new admin users.
How do I fix CVE-2025-54875?
To address CVE-2025-54875, upgrade FreshRSS to version 1.27.0 or later where the vulnerability has been patched.
Which versions of FreshRSS are affected by CVE-2025-54875?
FreshRSS versions 1.16.0 through 1.26.3 are affected by CVE-2025-54875.
What impact does CVE-2025-54875 have on FreshRSS users?
CVE-2025-54875 allows attackers to gain admin access, posing significant security risks to user data and system integrity.
Is registration enabled in FreshRSS a requirement for CVE-2025-54875?
Yes, for CVE-2025-54875 to be exploited, registration must be enabled in FreshRSS.