We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-32376

Discourse DM limits aren’t always properly enforced



Description

Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the beta branch, the users limit for a DM can be bypassed, thus giving the ability to potentially create a DM with every user from a site in it. This issue has been patched in stable version 3.4.3 and beta version 3.5.0.beta3.

Reserved 2025-04-06 | Published 2025-04-30 | Updated 2025-04-30 | Assigner GitHub_M


MEDIUM: 4.8CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L

Problem types

CWE-284: Improper Access Control

Product status

< 3.4.3
affected

>= 3.5.0.beta1, < 3.5.0.beta3
affected

References

github.com/...course/security/advisories/GHSA-mqqq-h2x3-46fr

github.com/...ommit/21a7f3162221c393f9bb13721451aa7f237d881a

cve.org (CVE-2025-32376)

nvd.nist.gov (CVE-2025-32376)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-32376

Support options

Helpdesk Chat, Email, Knowledgebase