PT-2025-4589 · Discourse · Discourse

Oiiwroo

+1

·

Published

2025-02-04

·

Updated

2025-09-25

·

CVE-2025-22601

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to the latest version
Description Discourse is an open source platform for community discussion. In affected versions, an attacker can trick a target user to make changes to their own username via a carefully crafted link using the activate-account route.
Recommendations For versions prior to the latest version, update to the latest version of Discourse to resolve the issue. As a temporary workaround, consider restricting access to the activate-account route until the update is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-22601
GHSA-GVPP-V7MP-WXXW

Affected Products

Discourse