High severity7.5NVD Advisory· Published Jun 25, 2025· Updated Jun 17, 2026
CVE-2025-49845
CVE-2025-49845
Description
Discourse is an open-source discussion platform. The visibility of posts typed whisper is controlled via the whispers_allowed_groups site setting. Only users that belong to groups specified in the site setting are allowed to view posts typed whisper. However, it has been discovered that users of versions prior to 3.4.6 on the stable branch and prior to 3.5.0.beta8-dev on the tests-passed branch can continue to see their own whispers even after losing visibility of posts typed whisper. This issue is patched in versions 3.4.6 and 3.5.0.beta8-dev. No known workarounds are available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*+ 2 more
- cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*range: <3.4.6
- (no CPE)range: <3.4.6, <3.5.0.beta8-dev
- (no CPE)range: < 3.4.6
Patches
Vulnerability mechanics
References
1- github.com/discourse/discourse/security/advisories/GHSA-79qw-r73r-69gfnvdVendor Advisory
News mentions
0No linked articles in our index yet.