{ "canonical_id": "discourse--6216e2732b", "system_id": "discourse", "display_name": "Discourse", "category": "cms", "advisory_mode": "core", "title": "3.5.2: Security and maintenance release", "summary": "

Discourse 3.5.2 Stable Release

\n

Discourse strongly recommends that all sites follow the default latest branch of Discourse. The \u201cstable\u201d branch is more focused on lack of change than lack of bugs - all releases, including those on latest and beta are production ready.

\n

Security Updates

\n

This release includes fixes for these security issues reported by our community and HackerOne.

\n\n

2 posts - 2 participants

\n

Read full topic

", "published_at": "Tue, 28 Oct 2025 07:33:40 +0000", "updated_at": "Tue, 28 Oct 2025 07:33:40 +0000", "severity": "unknown", "cvss_score": null, "exploit_status": "unknown", "source_confidence": "official", "official_source_url": "https://meta.discourse.org/t/3-5-2-security-and-maintenance-release/386388", "secondary_source_urls": [], "aliases": [], "cve_ids": [], "ghsa_ids": [], "osv_ids": [], "affected_versions": [], "fixed_versions": [], "package_name": null, "render_markdown": false, "case_path": null, "secure_code_topics": [ "authz-server-side-recheck", "xss-output-encoding", "plugin-extension-trust-policy", "dependency-upgrade-policy" ], "status": "triage", "triage_reasons": [ "missing affected/fixed version details" ], "verification_status": "triage-manual", "verification_mode": "synthetic", "last_verified_at": null, "last_run_id": null, "evidence_bundle": null, "historical_status": null, "latest_status": null, "browser_evidence": { "required": false, "present": false, "refs": [] }, "repro_profile_id": "xss-generic", "artifact_mode": "synthetic", "blocked_reason": null, "metadata": { "source_names": [ "Discourse Release Notes RSS" ], "source_kinds": [ "rss-feed" ], "candidate_count": 1 } }