CVE-2025-48954

Discourse is an open-source discussion platform. Versions prior to 3.5.0.beta6 are vulnerable to cross-site scripting when the content security policy isn't enabled when using social logins. Version 3.5.0.beta6 patches the issue. As a workaround, have the content security policy enabled.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:-:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:beta1:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:beta2:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:beta3:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:beta4:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:beta5:*:*:beta:*:*:*

History

25 Aug 2025, 15:04

Type Values Removed Values Added
CPE cpe:2.3:a:discourse:discourse:3.5.0:beta5:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:-:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:beta2:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:beta1:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:beta3:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:beta4:*:*:beta:*:*:*
References () https://github.com/discourse/discourse/security/advisories/GHSA-26p5-mjjh-wfcf - () https://github.com/discourse/discourse/security/advisories/GHSA-26p5-mjjh-wfcf - Vendor Advisory
First Time Discourse discourse
Discourse

26 Jun 2025, 18:57

Type Values Removed Values Added
Summary
  • (es) Discourse es una plataforma de discusión de código abierto. Las versiones anteriores a la 3.5.0.beta6 son vulnerables a ataques de cross-site scripting cuando la política de seguridad de contenido no está habilitada al usar inicios de sesión con redes sociales. La versión 3.5.0.beta6 soluciona el problema. Como solución alternativa, active la política de seguridad de contenido.

25 Jun 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-25 14:15

Updated : 2025-08-25 15:04


NVD link : CVE-2025-48954

Mitre link : CVE-2025-48954

CVE.ORG link : CVE-2025-48954


JSON object : View

Products Affected

discourse

  • discourse
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')