Vulnerability Description
Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even when `enable_names` is disabled. Versions 3.5.3, 2025.11.1, and 2025.12.0 contain a fix.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Discourse | Discourse | < 3.5.3 |
Related Weaknesses (CWE)
References
- https://github.com/discourse/discourse/commit/1cb45b8b287597085e3514596ffb1d9b41Patch
- https://github.com/discourse/discourse/commit/6192f55629624925595dae14364fd86cacPatch
- https://github.com/discourse/discourse/commit/e936a523b5900a9d866d23ea3da904ba12Patch
- https://github.com/discourse/discourse/security/advisories/GHSA-c59w-jwx7-34v4Third Party Advisory
FAQ
What is CVE-2025-64528?
CVE-2025-64528 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even w...
How severe is CVE-2025-64528?
CVE-2025-64528 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-64528?
Check the references section above for vendor advisories and patch information. Affected products include: Discourse Discourse.