CVE-2025-46824 - CVE House
Back to Database
Status published Low CVE-2025-46824

Discourse Code Review Plugin vulnerable to XSS via auto link commits

Vulnerability Description

The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users' browsers by posting links to malicious GitHub commits. This problem is patched in commit eed3a80 of the discourse-code-review plugin. As a workaround, one may disable the plugin.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-46824

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

discourse-code-review
Vulnerable Versions:
< eed3a80

Timeline

Official Publish: May 7th, 2025
Last Modified: August 20th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)