Open-Source Community Discussion Platform Vulnerability in Discourse
CVE-2025-59337
5.5MEDIUM
What is CVE-2025-59337?
Discourse, an open-source community discussion platform, is vulnerable in versions 3.5.0 and earlier due to an issue where malicious meta-commands could be included in backup dumps. When these backups are restored, they can execute harmful commands, which poses a significant risk, particularly in multisite environments where an admin for one site can potentially access sensitive data from other sites. This vulnerability has been remediated in version 3.5.1.
Affected Version(s)
discourse < 3.5.1