PT-2026-73255 · Bitnami · Discourse

Published

2026-08-17

·

Updated

2026-08-17

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox allowlist and embedded malicious content in a site. This issue is fixed in versions 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-DISCOURSE-2026-72728

Affected Products

Discourse