Cross-Site Scripting Flaw in Discourse Code Review Plugin
CVE-2025-46824

3.1LOW

Key Information:

Vendor

Discourse

Vendor
CVE Published:
7 May 2025

What is CVE-2025-46824?

The Discourse Code Review Plugin, which enables the review of GitHub commits within the Discourse platform, is susceptible to a cross-site scripting (XSS) vulnerability. Attackers can exploit this flaw by posting links to malicious GitHub commits that execute arbitrary JavaScript in users' browsers. This vulnerability was addressed in commit eed3a80, but until users apply the update, disabling the plugin can serve as a temporary workaround to safeguard against potential exploitation.

Affected Version(s)

discourse-code-review < eed3a80

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.