HTML Injection Flaw in Discourse Invitation System
CVE-2025-48062
7.1HIGH
What is CVE-2025-48062?
Discourse, an open-source discussion platform, has a vulnerability allowing HTML injection in the body of email invites. This issue arises when the topic title includes HTML, potentially affecting users invited to private messages and custom message topics. Specific versions prior to 3.4.4 for the stable branch and 3.5.0.beta5 for the beta branch are impacted. While a fix is available in the patched versions, users can mitigate the issue by overriding the relevant templates to avoid using the {topic_title}
placeholder.
Affected Version(s)
discourse < 3.4.4 < 3.4.4
discourse < 3.5.0.beta5 < 3.5.0.beta5
discourse < 3.5.0.beta6-dev < 3.5.0.beta6-dev