First published: Wed Apr 30 2025(Updated: )
Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the beta branch, the users limit for a DM can be bypassed, thus giving the ability to potentially create a DM with every user from a site in it. This issue has been patched in stable version 3.4.3 and beta version 3.5.0.beta3.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse | <3.4.3 | |
Discourse | <3.5.0.beta3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32376 is a medium severity vulnerability that allows users to bypass the direct messaging limit.
To fix CVE-2025-32376, upgrade Discourse to version 3.4.3 or later on the stable branch, or 3.5.0.beta3 or later on the beta branch.
CVE-2025-32376 affects Discourse versions prior to 3.4.3 on the stable branch and prior to 3.5.0.beta3 on the beta branch.
Yes, CVE-2025-32376 could potentially allow unauthorized users to create direct messages with every user on the site, leading to privacy violations.
CVE-2025-32376 was disclosed prior to the release of the patches for the affected versions of Discourse.