Information disclosure in Discourse - CVE-2026-33073
Published: July 1, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper isolation of stripe API keys in the discourse-subscriptions plugin when operating in a multisite cluster. A remote user can access stripe-related information from another site to disclose sensitive information.
Only multisite cluster deployments are affected.