Cross-Site Scripting Vulnerability in FreshRSS by FreshRSS
CVE-2025-32015

6.7MEDIUM

Key Information:

Vendor

Freshrss

Status
Vendor
CVE Published:
4 June 2025

What is CVE-2025-32015?

FreshRSS, a self-hosted RSS feed aggregator, suffers from a cross-site scripting (XSS) vulnerability due to improper HTML sanitization within the <iframe srcdoc> attribute. Before version 1.26.2, this weakness allowed attackers to execute their own JavaScript code by leveraging controlled feeds. By compromising a victim's feed and gaining access to their FreshRSS account, an attacker could perform actions such as deleting user accounts or executing arbitrary code on the server. The vulnerability was addressed in version 1.26.2.

Affected Version(s)

FreshRSS < 1.26.2

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.