Cross-site scripting in Discourse - #VU140003

 

Cross-site scripting in Discourse - #VU140003

Published: July 29, 2026


Vulnerability identifier: #VU140003
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Discourse

Detailed vulnerability description

The vulnerability allows a remote user to execute arbitrary script in the staff interface.

The vulnerability exists due to improper neutralization of input during web page generation in the staff action log rendering of previous and new value fields when rendering staff action log entries in the admin interface. A remote user can store crafted HTML or script in log values to execute arbitrary script in the staff interface.

User interaction is required for a staff user to view the affected interface.


Remediation

Install security update from vendor's website.

Sources