CVE-2025-68479: Discourse subscriptions are susceptible to takeover
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some subscription endpoints lack proper checking for ownership before making changes. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68479?
CVE-2025-68479 is considered to be a significant security vulnerability that can lead to subscription takeovers.
How do I fix CVE-2025-68479?
To fix CVE-2025-68479, upgrade Discourse to versions 3.5.4, 2025.11.2, 2025.12.1, or 2026.1.0 where the issue is patched.
What versions of Discourse are affected by CVE-2025-68479?
Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 of Discourse are affected by CVE-2025-68479.
What types of changes can lead to takeover in CVE-2025-68479?
CVE-2025-68479 allows unauthorized users to make ownership changes to subscription endpoints.
Is there a known exploit for CVE-2025-68479?
While there may be potential for exploitation due to the vulnerability, specific exploits have not been widely reported.