CVE-2025-67723 - CVE House
Back to Database
Status published Medium CVE-2025-67723

Discourse vulnerable to stored Cross-site Scripting via Katex in discourse-math plugin

Vulnerability Description

Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have a content-security-policy-mitigated cross-site scriptinv vulnerability on the Discourse Math plugin when using its KaTeX variant. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. As a workaround, the Discourse Math plugin can be disabled, or the Mathjax provider can be used instead of KaTeX.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-67723

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

discourse
Vulnerable Versions:
< 3.5.4, >= 2025.11.0-latest, < 2025.11.2, >= 2025.12.0-latest, < 2025.12.1, >= 2026.1.0-latest, < 2026.1.0

Timeline

Official Publish: January 28th, 2026
Last Modified: January 28th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L

Weaknesses (CWE)