CVE-2025-66488 | Discourse prior 3.5.4/2025.11.2/2026.1.0 authorized_extensions escape output (GHSA-68jp-3934-62rx)
A vulnerability identified as problematic has been detected in Discourse. The affected element is the function authorized_extensions. This manipulation causes escaping of output.
This vulnerability is handled as CVE-2025-66488. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.