HTML Injection Flaw in Discourse Invitation System
CVE-2025-48062

7.1HIGH

Key Information:

Vendor

Discourse

Status
Vendor
CVE Published:
9 June 2025

What is CVE-2025-48062?

Discourse, an open-source discussion platform, has a vulnerability allowing HTML injection in the body of email invites. This issue arises when the topic title includes HTML, potentially affecting users invited to private messages and custom message topics. Specific versions prior to 3.4.4 for the stable branch and 3.5.0.beta5 for the beta branch are impacted. While a fix is available in the patched versions, users can mitigate the issue by overriding the relevant templates to avoid using the {topic_title} placeholder.

Affected Version(s)

discourse < 3.4.4 < 3.4.4

discourse < 3.5.0.beta5 < 3.5.0.beta5

discourse < 3.5.0.beta6-dev < 3.5.0.beta6-dev

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.