PT-2026-73258 · Bitnami · Discourse
Published
2026-08-17
·
Updated
2026-08-17
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Discourse is an open-source discussion platform. From 2026.1.0 until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0, anyone able to run a parameterized Data Explorer query, including non-staff members of a group a query is shared with, could craft parameter values that escaped the intended query and executed arbitrary SQL through plugins/discourse-data-explorer/lib/discourse data explorer/data explorer.rb and plugins/discourse-data-explorer/lib/discourse data explorer/workflows/sql action/v1.rb. Recursive parameter interpolation allowed one parameter value to introduce another parameter, and parameter declarations in SQL comments could be used to inject a statement. Queries run in a read-only transaction, so data could not be modified, but any table could be read. This issue is fixed in versions 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Discourse