CVE-2025-46824

Source
https://cve.org/CVERecord?id=CVE-2025-46824
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-46824.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-46824
Aliases
  • GHSA-358v-cwvc-gxh5
Published
2025-05-07T17:37:56.214Z
Modified
2026-04-02T12:48:56.430638Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Discourse Code Review Plugin vulnerable to XSS via auto link commits
Details

The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users' browsers by posting links to malicious GitHub commits. This problem is patched in commit eed3a80 of the discourse-code-review plugin. As a workaround, one may disable the plugin.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/46xxx/CVE-2025-46824.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/discourse/discourse-code-review

Affected ranges

Type
GIT
Repo
https://github.com/discourse/discourse-code-review
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-46824.json"