CVE-2025-46824
Last modified
CVE-2025-46824 is a low-severity vulnerability rated 3.1/10 on the CVSS scale. The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users' browsers by posting links to malicious GitHub commits. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users' browsers by posting links to malicious GitHub commits. This problem is patched in commit eed3a80 of the discourse-code-review plugin. As a workaround, one may disable the plugin.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-46824?
How severe is CVE-2025-46824?
How do I fix CVE-2025-46824?
Are you affected by CVE-2025-46824?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
