CVE-2025-48053 Details
Description
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, sending a malicious URL in a PM to a bot user can cause a reduced the availability of a Discourse instance. This issue is patched in version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch. No known workarounds are available.
A denial-of-service vulnerability has been identified in Discourse, an open-source discussion platform. This issue affects versions prior to 3.4.4 of the stable branch, versions through 3.5.0.beta4 of the beta branch, and versions through 3.5.0.beta5-dev of the tests-passed branch. The vulnerability arises when a malicious URL is sent in a private message to a bot user, leading to a reduction in the availability of the Discourse instance.
Users can upgrade to Discourse version 3.4.4 or later on the stable branch, version 3.5.0.beta5 or later on the beta branch, or version 3.5.0.beta6-dev on the tests-passed branch.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/discourse/discourse/security/advisories/GHSA-3q5q-qmrm-rvwx | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| discourse discourse | < 3.4.4 < 3.5.0 3.5.0 beta1 3.5.0 beta2 3.5.0 beta3 3.5.0 beta4 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 25, 2025 | Reanalysis | [email protected] |
| Aug 25, 2025 | Initial Analysis | [email protected] |
| Jun 9, 2025 | New CVE Received | [email protected] |