CVE-2024-54142
CVSS 3.1 Score 9.0 of 10 (high)
Details
Published Jan 14, 2025
CWE ID 79
Summary
CVE-2024-54142 is a vulnerability affecting Discourse AI, a Discourse plugin offering AI features. When sharing Discourse AI Bot conversations into posts, any included HTML entities could leak into the Discourse application, posing a potential risk. This issue has been rectified through commit `92f122c`. Discourse users are strongly encouraged to apply updates as soon as possible. For those who cannot update, Discourse recommends removing all groups from the `ai bot public sharing allowed groups` site setting to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.