CVE-2025-48954: Discourse OAuth Social Login - Cross-site Scripting

HoneyLabs honeypots recorded 2 probes matching CVE-2025-48954 from 1 distinct source IP addresses in the last 7 days. Severity is rated high.

Request paths that identify it

  • /auth/failure

Addresses probing it

Source IPProbesNetworkCountry
93.123.109.2142Techoff Srv LimitedBulgaria

Networks it comes from

ASNOrganisationProbesSource IPs
AS48090Techoff Srv Limited21

Captured requests

  • /auth/failure?provider=%3Cmeta%20http-equiv%3D%22refresh%22%20content%3D%220%3Burl%3Dhttps%3A//evil.com%22%3E
  • /auth/failure?provider=<svg/onload=alert('XSS-CVE-2025-48954')>

CVE report

CVE report

Open a specific CVE from the CVE tracker.