Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31663 | FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below are vulnerable to directory enumeration by setting path in theme field, allowing attackers to gain additional information about the server by checking if certain directories exist. This issue is fixed in version 1.27.0. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 03 Oct 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:freshrss:freshrss:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 30 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Sep 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Freshrss
Freshrss freshrss |
|
| Vendors & Products |
Freshrss
Freshrss freshrss |
Mon, 29 Sep 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below are vulnerable to directory enumeration by setting path in theme field, allowing attackers to gain additional information about the server by checking if certain directories exist. This issue is fixed in version 1.27.0. | |
| Title | FreshRSS is vulnerable to directory enumeration by setting path in its theme field | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-30T14:31:02.217Z
Reserved: 2025-09-26T16:25:25.150Z
Link: CVE-2025-61586
Updated: 2025-09-30T14:30:56.440Z
Status : Analyzed
Published: 2025-09-30T04:44:53.067
Modified: 2025-10-03T15:39:40.233
Link: CVE-2025-61586
No data.
OpenCVE Enrichment
Updated: 2025-09-30T08:47:31Z
EUVD