WebAuthn Challenge Reuse Vulnerability in Discourse Community Platform
CVE-2025-53102
8.2HIGH
What is CVE-2025-53102?
Discourse, the open-source community discussion platform, has a vulnerability where the WebAuthn challenge issued during 2FA authentication is not cleared from the user's session after its use. This oversight can lead to the potential reuse of the challenge, presenting a security risk to user accounts. Users are advised to upgrade to version 3.4.7 or 3.5.0.beta.8 to mitigate this risk and enhance their security posture.
Affected Version(s)
discourse >= 3.5.0.beta1, < 3.5.0.beta.8 < 3.5.0.beta1, 3.5.0.beta.8
discourse < 3.4.7 < 3.4.7