Input validation error in Discourse - CVE-2026-55420
Published: July 1, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper input validation in PDF upload processing when handling uploaded PDF files under certain non-default configurations. A remote user can upload a specially crafted PDF file to execute arbitrary code.
Only installations using certain non-default configurations are vulnerable.