CVE-2025-48877CWE-1038

Discourse vulnerable to auto-executing of third-party code in embedded CodePen iframe

High · published June 9, 2025

CVSS v4.0
8.1
EPSS
0%
Percentile
31.1
In the wild
Unconfirmed
What it is

⚡ So close to a magical platform, but a sneaky iframe could let bad JavaScript slip right in! Before you know it, Codepen could run code you didn't intend it to. 🔥 Think of Discourse as a cozy café where the barista serves up delicious conversations. However, leaving an open window could let in a mischievous raccoon who tosses around unwanted ingredients in the café's recipes! If exploited, attackers could inject and execute any JavaScript within the iframe, potentially compromising user session data, altering content, or even redirecting users elsewhere - chaos in your cozy café! This vulnerability could lead to a serious breach of trust on your platform.

Put simply

Think of Discourse as a cozy café where the barista serves up delicious conversations. However, leaving an open window could let in a mischievous raccoon who tosses around unwanted ingredients in the café's recipes! This vulnerability arises because Codepen is included in the default `allowed_iframes` settings, allowing it to auto-run arbitrary JavaScript, which can lead to unauthorized actions in the context of your site. The risk is amplified because it’s part of the stable and beta branches of Discourse before the patch.

What to do

If exploited, attackers could inject and execute any JavaScript within the iframe, potentially compromising user session data, altering content, or even redirecting users elsewhere - chaos in your cozy café! This vulnerability could lead to a serious breach of trust on your platform. To protect your community, immediately update Discourse to version 3.4.4 (stable), 3.5.0.beta5 (beta), or 3.5.0.beta6-dev (tests-passed). Alternatively, you can manually remove the Codepen prefix from your site’s `allowed_iframes` setting as a temporary workaround. You've got this! Follow these steps, and you’ll be safeguarding your community in no time! 🛡️

The record
Technical detail
CVSS v4.0
8.1 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
EPSS
0.00380 · 31.1th percentile
Weakness
CWE-1038 · Insecure Automated Optimizations
Published
2025-06-09T12:36Z
EPSS history
Timeline
  • 09 JUN 12:36Z
    Discourse vulnerable to auto-executing of third-party code in embedded CodePen iframe
    cvelistv5