Open-Source Community Discussion Platform Vulnerability in Discourse
CVE-2025-59337

5.5MEDIUM

Key Information:

Vendor

Discourse

Status
Vendor
CVE Published:
1 October 2025

What is CVE-2025-59337?

Discourse, an open-source community discussion platform, is vulnerable in versions 3.5.0 and earlier due to an issue where malicious meta-commands could be included in backup dumps. When these backups are restored, they can execute harmful commands, which poses a significant risk, particularly in multisite environments where an admin for one site can potentially access sensitive data from other sites. This vulnerability has been remediated in version 3.5.1.

Affected Version(s)

discourse < 3.5.1

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59337 : Open-Source Community Discussion Platform Vulnerability in Discourse