The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users' browsers by posting links to malicious GitHub commits. This problem is patched in commit eed3a80 of the discourse-code-review plugin. As a workaround, one may disable the plugin.
CVE ID: CVE-2025-46824
CVSS Base Severity: LOW
CVSS Base Score: 3.1
CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Vendor: discourse
Product: discourse-code-review
EPSS Score: 0.03% (probability of being exploited)
EPSS Percentile: 7.68% (scored less or equal to compared to others)
EPSS Date: 2025-06-05 (when was this score calculated)