Data Leak Vulnerability in Discourse Community Platform
CVE-2025-46813
5.8MEDIUM
Key Information:
What is CVE-2025-46813?
The open-source community platform Discourse has a data leak vulnerability that affects login-required sites deployed within a specific timeframe. Sites launched between the specified commits may unintentionally expose private content on their homepages to users who have not logged in. This vulnerability impacts instances deployed from April 30, 2025, noon EDT to May 2, 2025, noon EDT. It is crucial for affected site administrators to upgrade to versions post the correction commit to safeguard their sites, as no workarounds are available.
Affected Version(s)
discourse >= 10df7fdee060d44accdee7679d66d778d1136510, <= 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b