CVE-2025-69218General(discourse / discourse)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can access the `top_uploads` admin report which should be restricted to admins only. This report displays direct URLs to all uploaded files on the site, including sensitive content such as user data exports, admin backups, and other private attachments that moderators should not have access to. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. There is no workaround. Limit moderator privileges to trusted users until the patch is applied.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • discourse

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-01-28); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
discourse

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-01-28: 1Mentions · 2026-01-29: 1Mentions · 2026-02-02: 1Technical Details · 2026-02-02: 101-2801-2902-02
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-281
General1
2026-01-291
General1
2026-02-021
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-69218 Unauthorized File URL Access in Discourse Admin Report for Moderators https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-69218

    Post summary

    The snippet merely announces CVE‑2025‑69218 with a brief descriptive title and no further information on exploitation, patches, or technical details.

    1000079
    4.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A vulnerability (CVE-2025-69218) in Discourse allows moderators to access private upload URLs via admin reports. Review access controls. #Discourse #infosec #Vulnerability https://www.pulsepatch.io/posts/cve-2025-69218-discourse-moderator-private-upload-urls

    Post summary

    The post announces CVE‑2025‑69218 in Discourse, detailing an access‑control flaw that lets moderators retrieve private upload URLs via admin reports, with no PoC, patch, or exploitation evidence provided.

    0000053
    1 followersView on X
  • CVE@CVEnew
    General

    CVE-2025-69218 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can access the `top_uploads` admin report … https://www.cve.org/CVERecord?id=CVE-2025-69218

    Post summary

    The post indicates that moderators in older Discourse versions can access a privileged admin report, but it provides no exploit details, patch information, or evidence of active exploitation.

    00000209
    56.5K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appdiscoursediscourse---
Appdiscoursediscourse2025.12.0--
Appdiscoursediscourse2026.1.0--

Explore more