Denial-of-Service Vulnerability in Discourse Discussion Platform
CVE-2025-48053
What is CVE-2025-48053?
This vulnerability affects the Discourse discussion platform, wherein a maliciously crafted URL sent through a private message to a bot user can degrade the availability of the Discourse instance. Affected versions include those prior to 3.4.4 in the stable branch, 3.5.0.beta5 in the beta branch, and 3.5.0.beta6-dev in the tests-passed branch. Users are urged to upgrade to the patched versions to mitigate potential disruptions, as no known workarounds exist.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
discourse < 3.4.4 < 3.4.4
discourse < 3.5.0.beta5 < 3.5.0.beta5
discourse < 3.5.0.beta6-dev < 3.5.0.beta6-dev
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved