CVE-2025-22602
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-22602 is a vulnerability affecting Discourse, an open-source community discussion platform. Malicious actors can exploit this issue by posting a malicious video placeholder html element, allowing them to execute arbitrary JavaScript on users' browsers. This vulnerability only poses a threat to sites with Content Security Policy (CSP) disabled. Discourse has released a patch to address this issue in its latest version. It is strongly recommended that users upgrade to the patched version to mitigate the risk. For those unable to upgrade immediately, enabling CSP is advised as a temporary measure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Discourse