CVE-2025-61586 | FreshRSS up to 1.26.x Setting theme path traversal (GHSA-w35p-p867-qr4f)
A vulnerability has been found in FreshRSS up to 1.26.x and classified as critical. The affected element is an unknown function of the component Setting Handler. Performing manipulation of the argument theme results in path traversal.
This vulnerability was named CVE-2025-61586. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.VulDB Recent EntriesRead More