PT-2026-73258 · Bitnami · Discourse

Published

2026-08-17

·

Updated

2026-08-17

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Discourse is an open-source discussion platform. From 2026.1.0 until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0, anyone able to run a parameterized Data Explorer query, including non-staff members of a group a query is shared with, could craft parameter values that escaped the intended query and executed arbitrary SQL through plugins/discourse-data-explorer/lib/discourse data explorer/data explorer.rb and plugins/discourse-data-explorer/lib/discourse data explorer/workflows/sql action/v1.rb. Recursive parameter interpolation allowed one parameter value to introduce another parameter, and parameter declarations in SQL comments could be used to inject a statement. Queries run in a read-only transaction, so data could not be modified, but any table could be read. This issue is fixed in versions 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-DISCOURSE-2026-72731

Affected Products

Discourse