CVE-2025-53532

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-53532
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53532.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-53532
Aliases
  • GHSA-w6vg-v24f-4vm3
Published
2025-07-07T17:15:30Z
Modified
2025-07-08T16:18:34Z
Summary
[none]
Details

giscus is a commenting system powered by GitHub Discussions. A bug in giscus' discussions creation API allowed an unauthorized user to create discussions on any repository where giscus is installed. This affects the server-side part of giscus, which is provided via http://giscus.app or your own self-hosted service. This vulnerability is fixed by the c43af7806e65adfcf4d0feeebef76dc36c95cb9a and 4b9745fe1a326ce08d69f8a388331bc993d19389 commits.

References

Affected packages

Git / github.com/giscus/giscus

Affected ranges

Type
GIT
Repo
https://github.com/giscus/giscus
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed