Cross-Site Scripting Flaw in Discourse Code Review Plugin
CVE-2025-46824
3.1LOW
Key Information:
- Vendor
Discourse
- Status
- Vendor
- CVE Published:
- 7 May 2025
What is CVE-2025-46824?
The Discourse Code Review Plugin, which enables the review of GitHub commits within the Discourse platform, is susceptible to a cross-site scripting (XSS) vulnerability. Attackers can exploit this flaw by posting links to malicious GitHub commits that execute arbitrary JavaScript in users' browsers. This vulnerability was addressed in commit eed3a80, but until users apply the update, disabling the plugin can serve as a temporary workaround to safeguard against potential exploitation.
Affected Version(s)
discourse-code-review < eed3a80