giscus is a commenting system powered by GitHub Discussions. A bug in giscus' discussions creation API allowed an unauthorized user to create discussions on any repository where giscus is installed. This affects the server-side part of giscus, which is provided via http://giscus.app or your own self-hosted service. This vulnerability is fixed by the c43af7806e65adfcf4d0feeebef76dc36c95cb9a and 4b9745fe1a326ce08d69f8a388331bc993d19389 commits.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Jul 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 07 Jul 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | giscus is a commenting system powered by GitHub Discussions. A bug in giscus' discussions creation API allowed an unauthorized user to create discussions on any repository where giscus is installed. This affects the server-side part of giscus, which is provided via http://giscus.app or your own self-hosted service. This vulnerability is fixed by the c43af7806e65adfcf4d0feeebef76dc36c95cb9a and 4b9745fe1a326ce08d69f8a388331bc993d19389 commits. | |
Title | giscus allows unauthorized discussion creation | |
Weaknesses | CWE-285 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-07T17:06:58.249Z
Updated: 2025-07-07T17:52:47.272Z
Reserved: 2025-07-02T15:15:11.514Z
Link: CVE-2025-53532

Updated: 2025-07-07T17:52:39.469Z

Status : Received
Published: 2025-07-07T17:15:30.533
Modified: 2025-07-07T17:15:30.533
Link: CVE-2025-53532

No data.