The following table lists the changes that have been made to the
CVE-2025-46824 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
New CVE Received
by [email protected]May. 07, 2025
Action Type Old Value New Value Added Description The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users’ browsers by posting links to malicious GitHub commits. This problem is patched in commit eed3a80 of the discourse-code-review plugin. As a workaround, one may disable the plugin. Added CVSS V3.1 AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N Added CWE CWE-79 Added Reference https://github.com/discourse/discourse-code-review/commit/eed3a801f8fee217fe782212d8950eb1bd236e43 Added Reference https://github.com/discourse/discourse-code-review/security/advisories/GHSA-358v-cwvc-gxh5