CVE-2025-31134

HIGH

FreshRSS <1.26.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, an attacker can gain additional information about the server by checking if certain directories exist. An attacker can, for example, check if older PHP versions are installed or if certain software is installed on the server and potentially use that information to further attack the server. Version 1.26.2 contains a patch for the issue.

Scores

CVSS v3 7.5
EPSS 0.0039
EPSS Percentile 60.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (1)
freshrss/freshrss < 1.26.2
Published Jun 04, 2025
Tracked Since Feb 18, 2026