CVE-2025-46824: Discourse Code Review Plugin vulnerable to XSS via auto link commits
The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users' browsers by posting links to malicious GitHub commits. This problem is patched in commit eed3a80 of the discourse-code-review plugin. As a workaround, one may disable the plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46824?
CVE-2025-46824 is classified as a security vulnerability that allows for the execution of arbitrary JavaScript on users' browsers.
How do I fix CVE-2025-46824?
To fix CVE-2025-46824, update the Discourse Code Review Plugin to the version including commit eed3a80.
What versions of the Discourse Code Review Plugin are affected by CVE-2025-46824?
CVE-2025-46824 affects all versions of the Discourse Code Review Plugin prior to commit eed3a80.
What type of attacks can be executed due to CVE-2025-46824?
CVE-2025-46824 allows attackers to post malicious links that execute arbitrary JavaScript in users' browsers.
Who is impacted by CVE-2025-46824?
Users of the Discourse Code Review Plugin prior to commit eed3a80 may be impacted by CVE-2025-46824.