CVE-2025-46824

LOW

Discourse Code Review Plugin <eed3a80 - XSS

Title source: llm
STIX 2.1

Description

The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users' browsers by posting links to malicious GitHub commits. This problem is patched in commit eed3a80 of the discourse-code-review plugin. As a workaround, one may disable the plugin.

Scores

CVSS v3 3.1
EPSS 0.0016
EPSS Percentile 36.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
discourse/discourse-code-review < eed3a80
Published May 07, 2025
Tracked Since Feb 18, 2026