PT-2026-98159 · Discourse · Discourse

CVE-2026-91122

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2026.1.8 Discourse versions prior to 2026.6.3 Discourse versions prior to 2026.7.2 Discourse versions prior to 2026.8.0
Description The video placeholder component allows crafted HTML to cause an attribute breakout and inject an attacker-controlled event handler. An authenticated user with default trust-level posting privileges can store the crafted placeholder in a post. When another user clicks the video play overlay, the handler executes arbitrary JavaScript in the viewer's session. While default Content Security Policy (CSP) settings block inline event handlers, instances with CSP disabled or relaxed may allow the script to read page content and make authenticated requests as the viewer. Content Security Policy is a security layer that helps detect and mitigate certain types of attacks, including Cross-Site Scripting (XSS).
Recommendations Update to version 2026.1.8 Update to version 2026.6.3 Update to version 2026.7.2 Update to version 2026.8.0

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91122
GHSA-8M44-F6G9-7CG7

Affected Products

Discourse