VYPR
Low severity3.1NVD Advisory· Published Feb 4, 2025· Updated Jun 17, 2026

CVE-2025-22601

CVE-2025-22601

Description

Discourse is an open source platform for community discussion. In affected versions an attacker can trick a target user to make changes to their own username via carefully crafted link using the activate-account route. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • beta: <= 3.4.0.beta3+ 5 more
    • (no CPE)range: beta: <= 3.4.0.beta3
    • cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*range: <3.4.0
    • cpe:2.3:a:discourse:discourse:3.4.0:beta1:*:*:beta:*:*:*
    • cpe:2.3:a:discourse:discourse:3.4.0:beta2:*:*:beta:*:*:*
    • cpe:2.3:a:discourse:discourse:3.4.0:beta3:*:*:beta:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.