FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during logout. After a user logs out, the session cookie remains active and unchanged. The unchanged cookie could be reused by an attacker if a new session were to be started. This failure to invalidate the session can lead to session hijacking and fixation vulnerabilities. This issue is fixed in version 1.27.0
History

Fri, 03 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:freshrss:freshrss:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 30 Sep 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Sep 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Freshrss
Freshrss freshrss
Vendors & Products Freshrss
Freshrss freshrss

Mon, 29 Sep 2025 21:30:00 +0000

Type Values Removed Values Added
Description FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during logout. After a user logs out, the session cookie remains active and unchanged. The unchanged cookie could be reused by an attacker if a new session were to be started. This failure to invalidate the session can lead to session hijacking and fixation vulnerabilities. This issue is fixed in version 1.27.0
Title FreshRSS has Incomplete Session Termination on Logout
Weaknesses CWE-613
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-09-29T21:23:43.903Z

Updated: 2025-09-30T13:42:14.955Z

Reserved: 2025-07-25T16:19:16.095Z

Link: CVE-2025-54592

cve-icon Vulnrichment

Updated: 2025-09-30T13:32:39.633Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-29T22:15:36.160

Modified: 2025-10-03T16:04:21.927

Link: CVE-2025-54592

cve-icon Redhat

No data.