Low severity3.1OSV Advisory· Published May 7, 2025· Updated Jun 17, 2026
CVE-2025-46824
CVE-2025-46824
Description
The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users' browsers by posting links to malicious GitHub commits. This problem is patched in commit eed3a80 of the discourse-code-review plugin. As a workaround, one may disable the plugin.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)
Patches
Vulnerability mechanics
References
4- github.com/discourse/discourse-code-review/commit/eed3a801f8fee217fe782212d8950eb1bd236e43nvd
- github.com/discourse/discourse-code-review/security/advisories/GHSA-358v-cwvc-gxh5nvd
- www.vicarius.io/vsociety/posts/cve-2025-46824-detect-discourse-plugin-vulnerabilitynvd
- www.vicarius.io/vsociety/posts/cve-2025-46824-mitigate-discourse-plugin-vulnerabilitynvd
News mentions
0No linked articles in our index yet.