Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-67723
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-67723 is a stored cross-site scripting (XSS) vulnerability in the Discourse Math plugin when using its KaTeX rendering variant. The vulnerability is partially mitigated by Content Security Policy (CSP) headers. It affects Discourse versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, and was disclosed on January 28, 2026. The CVSS v3.1 base score is 5.4 (Medium) per NVD, while the GitHub Security Advisory rates it 4.6 (Moderate) (GitHub Advisory, Red Hat).

Technical details

The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), specifically within the KaTeX math rendering path of the Discourse Math plugin. An authenticated attacker with low privileges can craft malicious input that, when rendered via KaTeX, injects and stores arbitrary JavaScript in the page. Exploitation requires user interaction — a victim must view the page containing the malicious math content — and the attack vector is network-based. The impact is partially constrained by Discourse's Content Security Policy, which limits the scope of script execution (GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker to inject persistent malicious scripts into Discourse forum pages, affecting any user who views the compromised content. The primary impacts are low-level integrity compromise (e.g., DOM manipulation, phishing overlays, session token theft if CSP is bypassed) and limited confidentiality exposure. Availability impact is also rated low. The CSP mitigates but does not fully eliminate the risk, as certain CSP configurations or browser behaviors may allow partial script execution (GitHub Advisory, Red Hat).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-67723. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a low-privileged authenticated account and victim interaction, further limiting practical exploitability (GitHub Advisory).

Exploitation steps

  1. Authenticate: Log in to a vulnerable Discourse instance (version < 3.5.4 or affected stable releases) with any low-privileged user account.
  2. Identify KaTeX usage: Confirm the Discourse Math plugin is enabled and configured to use the KaTeX provider (not MathJax).
  3. Craft malicious payload: Compose a forum post or topic containing a math block with a crafted KaTeX expression that embeds a malicious JavaScript payload within the rendered output.
  4. Post content: Submit the post to a publicly visible or targeted forum category, causing the payload to be stored server-side.
  5. Trigger victim interaction: Wait for or socially engineer a target user to view the post; upon rendering, the KaTeX variant processes the malicious input and executes the injected script in the victim's browser context (subject to CSP restrictions) (GitHub Advisory).

Indicators of compromise

  • Logs: Discourse application logs showing posts containing unusual or obfuscated content within math block delimiters (e.g., $$...$$ or \(...\)) from low-privileged accounts.
  • Network: Browser-side network requests to unexpected external domains originating from Discourse forum pages, potentially indicating exfiltration attempts if CSP is partially bypassed.
  • File System / Database: Forum posts in the Discourse database containing JavaScript event handlers or encoded script tags embedded within KaTeX math expressions.
  • Process/Application: CSP violation reports (if CSP reporting is enabled) logged for the Discourse domain, indicating attempted script execution blocked by policy (GitHub Advisory).

Mitigation and workarounds

Discourse has released patched versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, which address this vulnerability. Administrators unable to upgrade immediately should either disable the Discourse Math plugin entirely or switch the math rendering provider from KaTeX to MathJax in the plugin settings. Upgrading to a patched version is the recommended long-term remediation (GitHub Advisory).

Community reactions

The vulnerability received limited public attention, consistent with its moderate severity rating and CSP mitigation. A brief technical summary was published by Infinit Security (Infinit Security). No significant vendor statements beyond the GitHub Security Advisory or notable researcher commentary have been identified.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • gcc-toolset-15-binutils-devel
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management