Unrated severityNVD Advisory· Published Feb 4, 2025· Updated Feb 11, 2025
Client Side Path Traversal using activate account route in Discourse
CVE-2025-22601
Description
Discourse is an open source platform for community discussion. In affected versions an attacker can trick a target user to make changes to their own username via carefully crafted link using the activate-account route. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected products
1- Range: beta: <= 3.4.0.beta3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/discourse/discourse/security/advisories/GHSA-gvpp-v7mp-wxxwmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.