CVE-2025-53532: Giscus

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

giscus is a commenting system powered by GitHub Discussions. A bug in giscus' discussions creation API allowed an unauthorized user to create discussions on any repository where giscus is installed. This affects the server-side part of giscus, which is provided via http://giscus.app or your own self-hosted service. This vulnerability is fixed by the c43af7806e65adfcf4d0feeebef76dc36c95cb9a and 4b9745fe1a326ce08d69f8a388331bc993d19389 commits.

Affected products

  • Giscus Giscus: before c43af7806e65adfcf4d0feeebef76dc36c95cb9a (fixed in c43af7806e65adfcf4d0feeebef76dc36c95cb9a)

Published 2025-07-07. Last modified 2026-06-17.