CVE-2025-58054 LOW

CVE-2025-58054: Discourse is vulnerable to XSS when quoting chat messages

Vendor Discourse
Product discourse
Weakness CWE-80 · XSS · basic
Published October 1, 2025
Last update October 1, 2025

CVSS base score

3.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks through parsing and rendering of chat channel titles and chat thread titles via the quote message functionality when using the rich text editor. This issue is fixed in version 3.5.1.

Key dates

02Disclosure timeline

October 1, 2025 CVE published
October 1, 2025 Record updated