Low severity3.1NVD Advisory· Published Feb 4, 2025· Updated Jun 17, 2026
CVE-2025-22601
CVE-2025-22601
Description
Discourse is an open source platform for community discussion. In affected versions an attacker can trick a target user to make changes to their own username via carefully crafted link using the activate-account route. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6beta: <= 3.4.0.beta3+ 5 more
- (no CPE)range: beta: <= 3.4.0.beta3
- cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*range: <3.4.0
- cpe:2.3:a:discourse:discourse:3.4.0:beta1:*:*:beta:*:*:*
- cpe:2.3:a:discourse:discourse:3.4.0:beta2:*:*:beta:*:*:*
- cpe:2.3:a:discourse:discourse:3.4.0:beta3:*:*:beta:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
1- github.com/discourse/discourse/security/advisories/GHSA-gvpp-v7mp-wxxwnvdThird Party Advisory
News mentions
0No linked articles in our index yet.