HomeDiscourseCVE-2025-66488

CVE-2025-66488

MEDIUM
4.6CVSS
Published: 2026-01-28
Updated: 2026-01-30
AI Analysis

Description

Discourse is an open source discussion platform. A vulnerability present in versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 affects anyone who uses S3 for uploads. While scripts may be executed, they will only be run in the context of the S3/CDN domain, with no site credentials. Versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 fix the issue. As a workaround, disallow html or xml files for uploads in authorized_extensions. For existing html xml uploads, site owners can consider deleting them.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Attack Vector
network
Complexity
low
Privileges
low
User Action
required
Scope
unchanged
Confidentiality
none
Integrity
low
Availability
low
Weaknesses
CWE-116

Metadata

Primary Vendor
DISCOURSE
Published
1/28/2026
Last Modified
1/30/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

discourse : discoursediscourse : discoursediscourse : discoursediscourse : discourse

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-66488 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com