First published: Wed May 07 2025(Updated: )
The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users' browsers by posting links to malicious GitHub commits. This problem is patched in commit eed3a80 of the discourse-code-review plugin. As a workaround, one may disable the plugin.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse Code Review Plugin | <eed3a80 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46824 is classified as a security vulnerability that allows for the execution of arbitrary JavaScript on users' browsers.
To fix CVE-2025-46824, update the Discourse Code Review Plugin to the version including commit eed3a80.
CVE-2025-46824 affects all versions of the Discourse Code Review Plugin prior to commit eed3a80.
CVE-2025-46824 allows attackers to post malicious links that execute arbitrary JavaScript in users' browsers.
Users of the Discourse Code Review Plugin prior to commit eed3a80 may be impacted by CVE-2025-46824.