CVE-2025-46813: Private data leak on login-required Discourse sites

Published May 5, 2025
·
Updated

Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fdee060d44accdee7679d66d778d1136510 and 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b. On login-required sites, the leak meant that some content on the site's homepage could be visible to unauthenticated users. Only login-required sites that got deployed during this timeframe are affected, roughly between April 30 2025 noon EDT and May 2 2025, noon EDT. Sites on the stable branch are unaffected. Private content on an instance's homepage could be visible to unauthenticated users on login-required sites. Versions of 3.5.0.beta4 after commit 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b are not vulnerable to the issue. No workarounds are available. Sites must upgrade to a non-vulnerable version of Discourse.

Affected Software

5 affected components
Discourse Discourse>=10df7fdee060d44accdee7679d66d778d1136510<=82d84af6b0efbd9fa2aeec3e91ce7be1a768511b
Discourse Discourse<3.5.0
Discourse Discourse=3.5.0-beta1
Discourse Discourse=3.5.0-beta2
Discourse Discourse=3.5.0-beta3

Event History

May 5, 2025
CVE Published
via MITRE·08:03 PM
Data Sourced
via MITRE·08:03 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-46813?

CVE-2025-46813 is classified as a medium severity vulnerability due to potential data leakage on login-required Discourse sites.

2

How do I fix CVE-2025-46813?

To fix CVE-2025-46813, update your Discourse installation to a version beyond commit 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b.

3

What type of data is exposed in CVE-2025-46813?

CVE-2025-46813 may expose certain homepage content on Discourse sites that require user login.

4

Which Discourse versions are affected by CVE-2025-46813?

Discourse versions between commits 10df7fdee060d44accdee7679d66d778d1136510 and 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b are affected by CVE-2025-46813.

5

Can CVE-2025-46813 lead to unauthorized access?

CVE-2025-46813 does not directly lead to unauthorized access but may inadvertently leak sensitive content from protected pages.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203