CVE-2025-53102
Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5.0.beta.8 on the `tests-passed` branch, upon issuing a physical security key for 2FA, the server generates a WebAuthn challenge, which the client signs. The challenge is not cleared from the user’s session after authentication, potentially allowing reuse and increasing security risk. This is fixed in versions 3.4.7 and 3.5.0.beta.8.
- Affected products
- Discourse
- Discourse
- < 3.4.6, 3.5.0
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.5% (37th percentile)
- Weakness
- CWE-384
- NVD status
- Analyzed
- Published
- 2025-07-29
CVE-2025-53102 at NVD
No indexed exploits for CVE-2025-53102 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-53102 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.