VYPR
Unrated severityNVD Advisory· Published Feb 4, 2025· Updated Feb 11, 2025

Client Side Path Traversal using activate account route in Discourse

CVE-2025-22601

Description

Discourse is an open source platform for community discussion. In affected versions an attacker can trick a target user to make changes to their own username via carefully crafted link using the activate-account route. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.