We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the beta branch, the users limit for a DM can be bypassed, thus giving the ability to potentially create a DM with every user from a site in it. This issue has been patched in stable version 3.4.3 and beta version 3.5.0.beta3.
Reserved 2025-04-06 | Published 2025-04-30 | Updated 2025-04-30 | Assigner GitHub_MCWE-284: Improper Access Control
github.com/...course/security/advisories/GHSA-mqqq-h2x3-46fr
github.com/...ommit/21a7f3162221c393f9bb13721451aa7f237d881a
Support options