Unrated severityNVD Advisory· Published Apr 30, 2025· Updated Apr 30, 2025
Discourse DM limits aren’t always properly enforced
CVE-2025-32376
Description
Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the beta branch, the users limit for a DM can be bypassed, thus giving the ability to potentially create a DM with every user from a site in it. This issue has been patched in stable version 3.4.3 and beta version 3.5.0.beta3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3< 3.4.3 (stable), < 3.5.0.beta3 (beta)+ 1 more
- (no CPE)range: < 3.4.3 (stable), < 3.5.0.beta3 (beta)
- (no CPE)range: < 3.4.3
Patches
Vulnerability mechanics
References
2- github.com/discourse/discourse/commit/21a7f3162221c393f9bb13721451aa7f237d881amitrex_refsource_MISC
- github.com/discourse/discourse/security/advisories/GHSA-mqqq-h2x3-46frmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.