Vulnerability in FreshRSS Affects Self-hosted RSS Feed Aggregator
CVE-2025-46339

4.3MEDIUM

Key Information:

Vendor

Freshrss

Status
Vendor
CVE Published:
4 June 2025

What is CVE-2025-46339?

FreshRSS is a self-hosted RSS feed aggregator that allows users to set a proxy for fetching feeds. A vulnerability was discovered where an attacker could manipulate the favicon displayed for a feed by exploiting the proxy settings and disabling SSL verification. This manipulation occurs as the favicon hash is computed without accounting for the proxy address, protocol, or SSL verification status. As a result, threat actors can replace legitimate favicons with those of their choosing across all users' feeds, leading to potential misinformation and phishing risks. This issue was addressed in version 1.26.2.

Affected Version(s)

FreshRSS < 1.26.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.