CVE-2025-22601

CVSS 3.1 Score 3.1 of 10 (low)

Details

Published Feb 4, 2025
CWE ID 22

Summary

CVE-2025-22601 is a vulnerability affecting Discourse, an open-source platform for community discussions. Maliciously crafted links through the `activate-account` route can manipulate users into making changes to their own usernames. This issue, which allows attackers to exploit the trust of users, has been addressed in the latest version of Discourse. Users are strongly encouraged to upgrade as soon as possible, as there are currently no known workarounds to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share