CVE-2025-46824 Information
May 08, 2025
cve
Description
The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80 an attacker can execute arbitrary JavaScript on users’ browsers by posting links to malicious GitHub commits. This problem is patched in commit eed3a80 of the discourse-code-review plugin. As a workaround one may disable the plugin.
Reference
https://github.com/discourse/discourse-code-review/commit/eed3a801f8fee217fe782212d8950eb1bd236e43 https://github.com/discourse/discourse-code-review/security/advisories/GHSA-358v-cwvc-gxh5
Share on: