Description
The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users' browsers by posting links to malicious GitHub commits. This problem is patched in commit eed3a80 of the discourse-code-review plugin. As a workaround, one may disable the plugin.
References (4)
Core 4
Core References
Vendor Advisory x_refsource_confirm
https://github.com/discourse/discourse-code-review/security/advisories/GHSA-358v-cwvc-gxh5
Patch x_refsource_misc
https://github.com/discourse/discourse-code-review/commit/eed3a801f8fee217fe782212d8950eb1bd236e43
Scores
CVSS v3
3.1
EPSS
0.0016
EPSS Percentile
36.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
discourse/discourse-code-review
< eed3a80
Published
May 07, 2025
Tracked Since
Feb 18, 2026