PT-2025-3019 · Discourse · Discourse Ai
Jomaxro
+1
·
Published
2025-01-14
·
Updated
2025-01-15
·
CVE-2024-54142
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Discourse AI (affected versions not specified)
Description
The issue concerns the Discourse AI plugin, which provides AI features. When sharing conversations from the Discourse AI Bot into posts, HTML entities from the conversation could leak into the Discourse application if a user visits a post with a onebox for that conversation. This problem has been addressed in commit
92f122c.Recommendations
For all affected versions, update to a version that includes the fix from commit
92f122c.
As a temporary workaround for users unable to update, remove all groups from the ai bot public sharing allowed groups site setting.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse Ai