Code Execution Vulnerability in Folo by RSSNext
CVE-2025-53546
9.1CRITICAL
What is CVE-2025-53546?
Folo, a content feed organizer, contains a vulnerability that allows untrusted code execution due to misconfigurations in GitHub workflows. Exploiting this flaw can lead to unauthorized access to critical secrets, including the GITHUB_TOKEN, which has permission to modify repository content. This security issue emphasizes the need for secure coding practices and vigilant workflow management to prevent token leakage and unauthorized repository control. The issue has been addressed and resolved in a recent commit.
Affected Version(s)
Folo < 585c6a591440cd39f92374230ac5d65d7dd23d6a