CVE-2025-61586: FreshRSS is vulnerable to directory enumeration by setting path in its theme field
Published Sep 29, 2025
·Updated
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below are vulnerable to directory enumeration by setting path in theme field, allowing attackers to gain additional information about the server by checking if certain directories exist. This issue is fixed in version 1.27.0.
Affected Software
2 affected components
FreshRSS FreshRSS<1.27.0
FreshRSS FreshRSS<1.27.0
Remediation
Patch Available
Event History
Sep 29, 2025
CVE Published
via MITRE·11:14 PM
Data Sourced
via MITRE·11:14 PM
DescriptionWeakness
Sep 30, 2025
Data Sourced
via NVD·04:44 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-61586?
CVE-2025-61586 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2025-61586?
To fix CVE-2025-61586, upgrade FreshRSS to version 1.27.0 or later.
3
What is the impact of CVE-2025-61586?
CVE-2025-61586 allows attackers to perform directory enumeration, potentially disclosing sensitive information about the server.
4
Which versions of FreshRSS are affected by CVE-2025-61586?
FreshRSS versions 1.26.3 and below are affected by CVE-2025-61586.
5
Can CVE-2025-61586 be exploited remotely?
Yes, CVE-2025-61586 can be exploited remotely if an attacker can access the FreshRSS application.