CVE-2025-64528: Users are able to find users by name even when `enable_names` is off
Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even when enablenames is disabled. Versions 3.5.3, 2025.11.1, and 2025.12.0 contain a fix.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64528?
CVE-2025-64528 is considered a moderate severity vulnerability due to its potential for user information exposure.
How do I fix CVE-2025-64528?
To fix CVE-2025-64528, upgrade to Discourse version 3.5.3 or higher, or to 2025.11.1 or 2025.12.0.
What types of user information can be exposed by CVE-2025-64528?
CVE-2025-64528 allows attackers to retrieve a user's full name if they know part of the username, regardless of privacy settings.
In which versions of Discourse is CVE-2025-64528 present?
CVE-2025-64528 affects Discourse versions prior to 3.5.3, 2025.11.1, and 2025.12.0.
What are the potential impacts of exploiting CVE-2025-64528?
Exploiting CVE-2025-64528 can lead to unauthorized disclosure of personal user information, compromising user privacy.