CVE-2025-47288: Discourse Policy plugin private group members visible
Discourse Policy plugin gives the ability to confirm users have seen or done something. Prior to version 0.1.1, if there was a policy posted to a public topic that was tied to a private group then the group members could be shown to non-group members. This issue has been patched in version 0.1.1. A workaround involves moving any policy topics with private groups to restricted categories.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47288?
The severity of CVE-2025-47288 is considered to be moderate due to potential exposure of private group information.
How do I fix CVE-2025-47288?
To fix CVE-2025-47288, upgrade the Discourse Policy plugin to version 0.1.1 or later.
What are the consequences of not addressing CVE-2025-47288?
Failing to address CVE-2025-47288 may lead to unauthorized visibility of private group members to non-group users.
Who is affected by CVE-2025-47288?
Users of the Discourse Policy plugin prior to version 0.1.1 are affected by CVE-2025-47288.
Is there a workaround for CVE-2025-47288?
There is no official workaround for CVE-2025-47288; the best course of action is to update to the latest plugin version.