CVE-2025-59337 MEDIUM

CVE-2025-59337: Discourse: Cross-Site Data Exposure via Backup Restore Metacommand Injection in Multisite Deployments

Vendor Discourse
Product discourse
Weakness CWE-77
Published October 1, 2025
Last update October 2, 2025

CVSS base score

5.5/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H

What the vulnerability does

01Description

Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be embedded in a backup dump and executed during restore. In multisite setups, this allowed an admin of one site to access data or credentials from other sites. This issue is fixed in version 3.5.1.

Key dates

02Disclosure timeline

October 1, 2025 CVE published
October 2, 2025 Record updated