Vulnerability in FreshRSS Affects Self-hosted RSS Feed Aggregator
CVE-2025-46339
What is CVE-2025-46339?
FreshRSS is a self-hosted RSS feed aggregator that allows users to set a proxy for fetching feeds. A vulnerability was discovered where an attacker could manipulate the favicon displayed for a feed by exploiting the proxy settings and disabling SSL verification. This manipulation occurs as the favicon hash is computed without accounting for the proxy address, protocol, or SSL verification status. As a result, threat actors can replace legitimate favicons with those of their choosing across all users' feeds, leading to potential misinformation and phishing risks. This issue was addressed in version 1.26.2.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FreshRSS < 1.26.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
