Cross-site scripting in Discourse - #VU140004
Published: July 29, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script code in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the rich text editor transcript header rendering when processing chat transcript quote metadata. A remote user can supply a specially crafted username in quote metadata to execute arbitrary script code in a victim's browser.
User interaction is required to view the crafted content in the rich text editor.