Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-68932

34
FAUCET Score

CVE-2025-68932 is a critical vulnerability affecting FreshRSS, a self-hostable RSS aggregator, prior to version 1.28.0. The flaw stems from the use of cryptographically weak random number generators for remember-me tokens and nonces, enabling attackers to predict valid session tokens. This allows for persistent session hijacking and subsequent account takeover, as these tokens provide permanent authentication. Rated with a CVSS score of 9.8 (CRITICAL), this vulnerability has a low attack complexity and requires no user interaction, allowing for full compromise of confidentiality, integrity, and availability. The FAUCET Risk Score is 96/100, indicating a high potential for impact. While there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog, the vulnerability has garnered significant community discussion with 10 mentions, placing it in the top 1% of all CVEs for community attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.28.0CPE matchmatch criteria
cpe:2.3:a:freshrss:freshrss:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

2.9LOW

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.52%
Probability of exploitation in next 30 days
EPSS Percentile
41.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0052 is in the 18th percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / FreshRSS/FreshRSS/commit/57e1a375cbd2db9741ff19167813344f8eff5772
Patch
github.com / FreshRSS/FreshRSS/pull/8061
Issue TrackingPatch
github.com / FreshRSS/FreshRSS/security/advisories/GHSA-j9wc-gwc6-p786
ExploitPatchVendor Advisory