CVE-2025-46824 – Discourse Code Review Plugin Cross-Site Scripting (XSS)

The following table lists the changes that have been made to the
CVE-2025-46824 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    May. 07, 2025

    Action Type Old Value New Value
    Added Description The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users’ browsers by posting links to malicious GitHub commits. This problem is patched in commit eed3a80 of the discourse-code-review plugin. As a workaround, one may disable the plugin.
    Added CVSS V3.1 AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
    Added CWE CWE-79
    Added Reference https://github.com/discourse/discourse-code-review/commit/eed3a801f8fee217fe782212d8950eb1bd236e43
    Added Reference https://github.com/discourse/discourse-code-review/security/advisories/GHSA-358v-cwvc-gxh5
Share the Post:

Related Posts