CVE-2025-68660 | Discourse prior 3.5.4/2025.11.2/2025.12.1/2026.1.0 ai_discover_persona authorization (GHSA-mrvm-rprq-jqqh)
A vulnerability, which was classified as critical, has been found in Discourse. Affected by this issue is the function ai_discover_persona. This manipulation causes incorrect authorization.
This vulnerability is tracked as CVE-2025-68660. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.