PT-2025-3268 · Discourse · Discourse

Jomaxro

·

Published

2025-02-04

·

Updated

2025-09-26

·

CVE-2024-56328

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Discourse (affected versions not specified)
Description The issue allows an attacker to execute arbitrary JavaScript code in users' browsers by posting a maliciously crafted Onebox URL. This problem only affects sites with Content Security Policy (CSP) disabled. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited. The technical details about exploitation include the use of a malicious Onebox URL to execute arbitrary JavaScript code.
Recommendations For all affected versions, update to the latest version of Discourse to resolve the issue. As a temporary workaround, consider enabling CSP, disabling inline Oneboxes globally, or allowing specific domains for Oneboxing until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2024-56328
CVE-2024-56328
GHSA-J855-MHXJ-X6VG

Affected Products

Discourse