Data Leak Vulnerability in Discourse Community Platform
CVE-2025-46813

5.8MEDIUM

Key Information:

Vendor

Discourse

Status
Vendor
CVE Published:
5 May 2025

What is CVE-2025-46813?

The open-source community platform Discourse has a data leak vulnerability that affects login-required sites deployed within a specific timeframe. Sites launched between the specified commits may unintentionally expose private content on their homepages to users who have not logged in. This vulnerability impacts instances deployed from April 30, 2025, noon EDT to May 2, 2025, noon EDT. It is crucial for affected site administrators to upgrade to versions post the correction commit to safeguard their sites, as no workarounds are available.

Affected Version(s)

discourse >= 10df7fdee060d44accdee7679d66d778d1136510, <= 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.