CNNVD-202601-4697 Information

CNNVD ID

CNNVD-202601-4697

CVE-2025-66488

  • CNNVD Published: 2026-01-28

Description (Chinese)

Discourse是Discourse开源的一套开源的社区讨论平台。该平台包括社区、电子邮件和聊天室等功能。 Discourse 3.5.4之前版本、2025.11.2之前版本、2025.12.1之前版本和2026.1.0之前版本存在安全漏洞,该漏洞源于使用S3上传时可能执行脚本,可能导致跨站脚本攻击。

Description (English)

Discourse is an open-source community discussion platform for Discourse. The platform includes community, e-mail and chat rooms. There is a security loophole in previous versions of Discourse 3.5.4, before 2025.11.2, before 2025.12.1 and before 2026.1.0, which stems from the possibility of implementing scripts when using S3 uploads, which could lead to cross-site script attacks.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Discourse

Published

2026-01-28

Last Modified

2026-02-24

References

https://github.com/discourse/discourse/security/advisories/GHSA-68jp-3934-62rx https://access.redhat.com/security/cve/cve-2025-66488

Patch

https://github.com/discourse/discourse/tags

Share on: