CVE-2024-24748: Discourse

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a public category which has no public subcategories. The issue is patched in the latest stable, beta and tests-passed version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected products

  • Discourse Discourse: up to and including 3.2.0; version 3.2.0 only; version 3.3.0 only

Published 2024-03-15. Last modified 2026-06-17.