Unrated severityNVD Advisory· Published Nov 14, 2022· Updated Apr 23, 2025
Users erroneously and transparently added to private messages in Discourse
CVE-2022-39385
Description
Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a participant to several private message topics that they should not be added to. They are not notified of this, it happens transparently in the background. This issue has been resolved in commit a414520742 and will be included in future releases. Users are advised to upgrade. Users are also advised to set SiteSetting.max_invites_per_day to 0 until the patch is installed.
Affected products
1- Range: Stable: <= 2.8.10
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.