PT-2026-98159 · Discourse · Discourse
CVE-2026-91122
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to 2026.1.8
Discourse versions prior to 2026.6.3
Discourse versions prior to 2026.7.2
Discourse versions prior to 2026.8.0
Description
The video placeholder component allows crafted HTML to cause an attribute breakout and inject an attacker-controlled event handler. An authenticated user with default trust-level posting privileges can store the crafted placeholder in a post. When another user clicks the video play overlay, the handler executes arbitrary JavaScript in the viewer's session. While default Content Security Policy (CSP) settings block inline event handlers, instances with CSP disabled or relaxed may allow the script to read page content and make authenticated requests as the viewer. Content Security Policy is a security layer that helps detect and mitigate certain types of attacks, including Cross-Site Scripting (XSS).
Recommendations
Update to version 2026.1.8
Update to version 2026.6.3
Update to version 2026.7.2
Update to version 2026.8.0
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse