PT-2025-54189 · Discourse · Discourse

Davidtaylorhq

·

Published

2025-12-30

·

Updated

2026-02-20

·

CVE-2025-64528

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.5.3 Discourse versions prior to 2025.11.1 Discourse versions prior to 2025.12.0
Description Discourse is an open source discussion platform. An attacker who knows part of a username can find the user and their full name via the user interface or API, even when enable names is disabled. The issue occurs when an attacker knows a portion of a user’s username.
Recommendations Update to Discourse version 3.5.3 or later. Update to Discourse version 2025.11.1 or later. Update to Discourse version 2025.12.0 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2025-64528
CVE-2025-64528
GHSA-C59W-JWX7-34V4

Affected Products

Discourse