CVE-2025-48877 is a critical vulnerability affecting Discourse, an open-source discussion platform, specifically versions prior to 3.4.4 (stable), 3.5.0.beta5 (beta), and 3.5.0.beta6-dev (tests-passed). The vulnerability stems from Codepen being included in the default allowed_iframes setting, which could allow for unintended auto-execution of arbitrary JavaScript within the iframe scope. With a CVSS score of 9.8 (CRITICAL), this vulnerability has a network attack vector, low attack complexity, and high potential impact on confidentiality, integrity, and availability. The FAUCET Risk Score is 87/100, indicating significant risk. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules for Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, which is typical for a large percentage of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.4.4CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:* | ||
< 3.5.0CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:* | ||
3.5.0CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:3.5.0:beta1:*:*:beta:*:*:* | ||
3.5.0CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:3.5.0:beta2:*:*:beta:*:*:* | ||
3.5.0CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:3.5.0:beta3:*:*:beta:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.