Cross-Site Scripting Vulnerability in FreshRSS by FreshRSS
CVE-2025-32015
6.7MEDIUM
What is CVE-2025-32015?
FreshRSS, a self-hosted RSS feed aggregator, suffers from a cross-site scripting (XSS) vulnerability due to improper HTML sanitization within the <iframe srcdoc>
attribute. Before version 1.26.2, this weakness allowed attackers to execute their own JavaScript code by leveraging controlled feeds. By compromising a victim's feed and gaining access to their FreshRSS account, an attacker could perform actions such as deleting user accounts or executing arbitrary code on the server. The vulnerability was addressed in version 1.26.2.
Affected Version(s)
FreshRSS < 1.26.2