CVE-2025-31136
Last modified
CVE-2025-31136 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to run arbitrary JavaScript on the feeds page. This occurs by combining a cross-site scripting (XSS) issue that occurs in `f.php` when SVG favicons are downloaded from an attacker-controlled feed containing `<script>` tags inside of them that aren't sanitized, with the lack of CSP in `f.php` by embedding the malicious favicon in an iframe (that has `sandbox="allow-scripts allow-same-origin"` set as its attribute). EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to run arbitrary JavaScript on the feeds page. This occurs by combining a cross-site scripting (XSS) issue that occurs in `f.php` when SVG favicons are downloaded from an attacker-controlled feed containing `<script>` tags inside of them that aren't sanitized, with the lack of CSP in `f.php` by embedding the malicious favicon in an iframe (that has `sandbox="allow-scripts allow-same-origin"` set as its attribute). An attacker needs to control one of the feeds that the victim is subscribed to, and also must have an account on the FreshRSS instance. Other than that, the iframe payload can be embedded as one of two options. The first payload requires user interaction (the user clicking on the malicious feed entry) with default user configuration, and the second payload fires instantly right after the user adds the feed or logs into the account while the feed entry is still visible. This is because of lazy image loading functionality, which the second payload bypasses. An attacker can gain access to the victim's account by exploiting this vulnerability. If the victim is an admin it would be possible to delete all users (cause damage) or execute arbitrary code on the server by modifying the update URL using fetch() via the XSS. Version 1.26.2 has a patch for the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Freshrss | Freshrss | < 1.26.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-31136?
How severe is CVE-2025-31136?
How do I fix CVE-2025-31136?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-31130gitoxide is an implementation of git written in Rust. Before…6.8
- CVE-2025-31131YesWiki is a wiki system written in PHP. The squelette param…7.5
- CVE-2025-31132Raven is an open-source messaging platform. A vulnerability …8.1
- CVE-2025-31133runc is a CLI tool for spawning and running containers accor…7.8
- CVE-2025-31134FreshRSS is a self-hosted RSS feed aggregator. Prior to vers…7.5
- CVE-2025-31135Go-Guerrilla SMTP Daemon is a lightweight SMTP server writte…5.3
- CVE-2025-31137React Router is a multi-strategy router for React bridging t…7.5
- CVE-2025-31138tarteaucitron.js is a compliant and accessible cookie banner…6.6
- CVE-2025-31139In JetBrains TeamCity before 2025.03 base64 encoded password…6.5
- CVE-2025-3114Code Execution via Malicious Files: Attackers can create spe…9.4
- CVE-2025-31140In JetBrains TeamCity before 2025.03 stored XSS was possible…6.1
- CVE-2025-31141In JetBrains TeamCity before 2025.03 exception could lead to…7.5
Are you affected by CVE-2025-31136?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
