CVE-2025-68479 | Discourse prior 3.5.4/2025.11.2/2025.12.1/2026.1.0 Subscription authorization (GHSA-6gjr-5897-m327)
A vulnerability classified as critical has been found in Discourse. Affected is an unknown function of the component Subscription Handler. The manipulation leads to missing authorization.
This vulnerability is referenced as CVE-2025-68479. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.