Unrated severityNVD Advisory· Published Apr 30, 2025· Updated Apr 30, 2025
Discourse DM limits aren’t always properly enforced
CVE-2025-32376
Description
Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the beta branch, the users limit for a DM can be bypassed, thus giving the ability to potentially create a DM with every user from a site in it. This issue has been patched in stable version 3.4.3 and beta version 3.5.0.beta3.
Affected products
1- Range: < 3.4.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/discourse/discourse/commit/21a7f3162221c393f9bb13721451aa7f237d881amitrex_refsource_MISC
- github.com/discourse/discourse/security/advisories/GHSA-mqqq-h2x3-46frmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.