SB2026072957 - Multiple vulnerabilities in Discourse
Published: July 29, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 16 vulnerabilities.
1) Improper access control (CVE-ID: CVE-2026-53960)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the Q&A schema JSON-LD structured data generation when serving QAPage JSON-LD for topics with hidden or otherwise unviewable first-post content. A remote attacker can request the affected page to disclose sensitive information.
The leaked content was exposed to unauthenticated visitors and search-engine crawlers.
2) Cross-site scripting (CVE-ID: CVE-2026-55674)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to execute arbitrary script in victims' browsers.
The vulnerability exists due to improper neutralization of input during web page generation in the color scheme tag rendering logic when processing crafted color_scheme_id or dark_scheme_id cookie values. A remote attacker can send a specially crafted request with a malicious cookie value to execute arbitrary script in victims' browsers.
The poisoned response can be cached and served to subsequent anonymous visitors, scoped per User-Agent.
3) Improper access control (CVE-ID: CVE-2026-55704)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the group posts and group mentions endpoints when serializing group activity. A remote user can access those endpoints to disclose shared-draft topic titles and post excerpt/content.
Only users allowed to view a group's activity but not permitted to see shared drafts are able to access the leaked unpublished draft material.
4) Cross-site scripting (CVE-ID: CVE-2026-59830)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary script code in the victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in post actions on user activity streams when rendering user-controlled display names in an HTML string passed to trustHTML. A remote user can set a crafted actor name to execute arbitrary script code in the victim's browser.
User interaction is required to view the affected activity stream.
5) Improper access control (CVE-ID: CVE-2026-59829)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the review queue when displaying flag-related private message excerpts and permalinks. A remote user can access the review queue to disclose sensitive information.
Only sites with category group moderation enabled are affected. The exposure is limited to excerpts and permalinks of notify_moderators flag messages, including cases involving core flags raised before a moderator's group was granted moderation of the category.
6) Improper access control (CVE-ID: N/A)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to disclose private chat thread messages.
The vulnerability exists due to improper access control in the onebox endpoint when handling onebox requests with a public chat channel ID paired with a private thread ID. A remote user can send a crafted onebox request to disclose private chat thread messages.
7) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary script in the staff interface.
The vulnerability exists due to improper neutralization of input during web page generation in the staff action log rendering of previous and new value fields when rendering staff action log entries in the admin interface. A remote user can store crafted HTML or script in log values to execute arbitrary script in the staff interface.
User interaction is required for a staff user to view the affected interface.
8) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary script code in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the rich text editor transcript header rendering when processing chat transcript quote metadata. A remote user can supply a specially crafted username in quote metadata to execute arbitrary script code in a victim's browser.
User interaction is required to view the crafted content in the rich text editor.
9) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary script code in a user's browser.
The vulnerability exists due to cross-site scripting in the moderation review queue when rendering stored content. A remote user can submit specially crafted content to execute arbitrary script code in a user's browser.
This vulnerability only affects sites that have modified or disabled the default Content Security Policy, and user interaction is required.
10) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to cross-site scripting in the discourse-local-dates plugin when rendering stored content. A remote user can inject a crafted payload to execute arbitrary script in the victim's browser.
This vulnerability only affects sites that have modified or disabled the default Content Security Policy, and user interaction is required.
11) Improper Handling of Case Sensitivity (CVE-ID: N/A)
CWE-ID: CWE-178 - Improper Handling of Case Sensitivity
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper input validation in the Onebox domain blocklist comparison logic when processing redirect targets. A remote attacker can use case variations in a hostname to bypass domain restrictions and disclose sensitive information.
12) Improper access control (CVE-ID: N/A)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the SiteSerializer default navigation menu tag serialization when generating the anonymous site configuration response. A remote attacker can request the anonymous site configuration response to disclose sensitive information.
Tag names and descriptions restricted to inaccessible categories may be exposed.
13) Improper access control (CVE-ID: N/A)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to disclose restricted topic and private message titles.
The vulnerability exists due to improper access control in internal link extraction and duplicate lookup when processing canonicalized internal URLs. A remote user can submit or reference crafted internal URLs to disclose restricted topic and private message titles.
14) Improper access control (CVE-ID: N/A)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to disclose hidden tag names.
The vulnerability exists due to improper access control in the templates endpoint when handling requests for serialized tags. A remote user can send a request to disclose hidden tag names.
The serializer does not correctly respect tag group permissions.
15) Improper access control (CVE-ID: N/A)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in private AI bot conversations when handling conversation access requests. A remote user can access private AI bot conversations to disclose sensitive information.
16) Improper access control (CVE-ID: N/A)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in Discourse AI reviewables when handling reviewables associated with private messages. A remote privileged user can access a reviewable in the moderator review queue to disclose sensitive information.
User interaction is required, and exploitation requires a pre-existing Discourse AI reviewable associated with a private message.
Remediation
Install update from vendor's website.
References
- https://github.com/discourse/discourse/security/advisories/GHSA-j5j7-w5g3-43q8
- https://github.com/discourse/discourse/security/advisories/GHSA-qx4v-rg4v-pm2g
- https://github.com/discourse/discourse/security/advisories/GHSA-fxw4-38v9-76v8
- https://github.com/discourse/discourse/security/advisories/GHSA-x6mf-p7cg-69rw
- https://github.com/discourse/discourse/security/advisories/GHSA-wmc6-pmxp-xw5w
- https://github.com/discourse/discourse/security/advisories/GHSA-8g98-fvfc-9w48
- https://github.com/discourse/discourse/security/advisories/GHSA-8x29-vv56-wj6v
- https://github.com/discourse/discourse/security/advisories/GHSA-wg48-qxjc-f459
- https://github.com/discourse/discourse/security/advisories/GHSA-pq6q-p5g3-rj54
- https://github.com/discourse/discourse/security/advisories/GHSA-rw96-2xg7-h54g
- https://github.com/discourse/discourse/security/advisories/GHSA-3x7x-24rq-h5j6
- https://github.com/discourse/discourse/security/advisories/GHSA-4p6q-h74v-5j7p
- https://github.com/discourse/discourse/security/advisories/GHSA-4fx9-5m29-83p4
- https://github.com/discourse/discourse/security/advisories/GHSA-xrgc-52m8-82hm
- https://github.com/discourse/discourse/security/advisories/GHSA-gw88-2jw8-jf2h
- https://github.com/discourse/discourse/security/advisories/GHSA-3rx9-fqgh-wfpc