Vulnerability in FreshRSS Affects Self-hosted RSS Feed Aggregator
CVE-2025-46339
4.3MEDIUM
What is CVE-2025-46339?
FreshRSS is a self-hosted RSS feed aggregator that allows users to set a proxy for fetching feeds. A vulnerability was discovered where an attacker could manipulate the favicon displayed for a feed by exploiting the proxy settings and disabling SSL verification. This manipulation occurs as the favicon hash is computed without accounting for the proxy address, protocol, or SSL verification status. As a result, threat actors can replace legitimate favicons with those of their choosing across all users' feeds, leading to potential misinformation and phishing risks. This issue was addressed in version 1.26.2.
Affected Version(s)
FreshRSS < 1.26.2