PT-2025-4590 · Discourse · Discourse

Taisehub

·

Published

2025-02-04

·

Updated

2025-09-26

·

CVE-2025-22602

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Discourse versions prior to the latest version
Description Discourse is an open source platform for community discussion. In affected versions, an attacker can execute arbitrary JavaScript on users' browsers by posting a malicious video placeholder HTML element. This issue only affects sites with CSP disabled.
Recommendations For versions prior to the latest version, update to the latest version to resolve the issue. As a temporary workaround for users unable to upgrade, enable CSP to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2025-22602
CVE-2025-22602
GHSA-JCJX-694P-C5M3

Affected Products

Discourse