Code Execution Vulnerability in Folo by RSSNext
CVE-2025-53546

9.1CRITICAL

Key Information:

Vendor

Rssnext

Status
Vendor
CVE Published:
9 July 2025

What is CVE-2025-53546?

Folo, a content feed organizer, contains a vulnerability that allows untrusted code execution due to misconfigurations in GitHub workflows. Exploiting this flaw can lead to unauthorized access to critical secrets, including the GITHUB_TOKEN, which has permission to modify repository content. This security issue emphasizes the need for secure coding practices and vigilant workflow management to prevent token leakage and unauthorized repository control. The issue has been addressed and resolved in a recent commit.

Affected Version(s)

Folo < 585c6a591440cd39f92374230ac5d65d7dd23d6a

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53546 : Code Execution Vulnerability in Folo by RSSNext