PT-2025-40288 · Discourse · Discourse

Tgxworld

·

Published

2025-10-01

·

Updated

2025-10-23

·

CVE-2025-58054

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.5.1
Description Discourse, an open-source community discussion platform, is affected by a cross-site scripting (XSS) issue. The issue stems from how the platform parses and renders chat channel titles and chat thread titles using the quote message functionality with the rich text editor. This allows for the execution of malicious scripts through crafted titles.
Recommendations Update to version 3.5.1 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2025-58054
CVE-2025-58054
GHSA-7P47-8M82-M2VF

Affected Products

Discourse