VYPR
High severity7.5NVD Advisory· Published Jun 4, 2025· Updated Jun 17, 2026

CVE-2025-31134

CVE-2025-31134

Description

FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, an attacker can gain additional information about the server by checking if certain directories exist. An attacker can, for example, check if older PHP versions are installed or if certain software is installed on the server and potentially use that information to further attack the server. Version 1.26.2 contains a patch for the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • FreshRSS/Freshrss3 versions
    cpe:2.3:a:freshrss:freshrss:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:freshrss:freshrss:*:*:*:*:*:*:*:*range: <1.26.2
    • (no CPE)range: <1.26.2
    • (no CPE)range: < 1.26.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.