
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67723 is a stored cross-site scripting (XSS) vulnerability in the Discourse Math plugin when using its KaTeX rendering variant. The vulnerability is partially mitigated by Content Security Policy (CSP) headers. It affects Discourse versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, and was disclosed on January 28, 2026. The CVSS v3.1 base score is 5.4 (Medium) per NVD, while the GitHub Security Advisory rates it 4.6 (Moderate) (GitHub Advisory, Red Hat).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), specifically within the KaTeX math rendering path of the Discourse Math plugin. An authenticated attacker with low privileges can craft malicious input that, when rendered via KaTeX, injects and stores arbitrary JavaScript in the page. Exploitation requires user interaction — a victim must view the page containing the malicious math content — and the attack vector is network-based. The impact is partially constrained by Discourse's Content Security Policy, which limits the scope of script execution (GitHub Advisory).
Successful exploitation allows an authenticated attacker to inject persistent malicious scripts into Discourse forum pages, affecting any user who views the compromised content. The primary impacts are low-level integrity compromise (e.g., DOM manipulation, phishing overlays, session token theft if CSP is bypassed) and limited confidentiality exposure. Availability impact is also rated low. The CSP mitigates but does not fully eliminate the risk, as certain CSP configurations or browser behaviors may allow partial script execution (GitHub Advisory, Red Hat).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-67723. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a low-privileged authenticated account and victim interaction, further limiting practical exploitability (GitHub Advisory).
$$...$$ or \(...\)) from low-privileged accounts.Discourse has released patched versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, which address this vulnerability. Administrators unable to upgrade immediately should either disable the Discourse Math plugin entirely or switch the math rendering provider from KaTeX to MathJax in the plugin settings. Upgrading to a patched version is the recommended long-term remediation (GitHub Advisory).
The vulnerability received limited public attention, consistent with its moderate severity rating and CSP mitigation. A brief technical summary was published by Infinit Security (Infinit Security). No significant vendor statements beyond the GitHub Security Advisory or notable researcher commentary have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."