CVE-2025-59950: FreshRSS: Double clickjacking can lead to privilege escalation
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking protection (confirmation dialog), it is possible to trick the admin into clicking the Promote button in another user's management page after the admin double clicks on a button inside an attacker-controlled website. A successful attack can allow the attacker to promote themselves to "admin" and log into other users' accounts; the attacker has to know the specific instance URL they're targeting. This issue is fixed in version 1.27.0.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59950?
CVE-2025-59950 has a severity rating that indicates a significant risk due to its potential for bypassing double clickjacking protection.
How do I fix CVE-2025-59950?
To fix CVE-2025-59950, update FreshRSS to version 1.27.0 or later.
What versions of FreshRSS are affected by CVE-2025-59950?
CVE-2025-59950 affects FreshRSS versions 1.26.3 and below.
What is double clickjacking as it relates to CVE-2025-59950?
Double clickjacking in CVE-2025-59950 refers to a method of tricking the admin into performing actions unknowingly through a UI exploit.
Who is affected by CVE-2025-59950?
Administrators of FreshRSS versions 1.26.3 and below are primarily affected by CVE-2025-59950.