PT-2026-98160 · Discourse · Discourse
CVE-2026-91123
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to 2026.1.8
Discourse versions prior to 2026.6.3
Discourse versions prior to 2026.7.2
Discourse versions prior to 2026.8.0
Description
The iframe src traversal guard fails to treat literal backslashes as path separators following decoded dot segments. This allows a crafted source to bypass the
allowed iframes subpath check because browser URL normalization can move the iframe outside the intended allowed path, enabling the loading of content from unauthorized locations.Recommendations
Update to version 2026.1.8
Update to version 2026.6.3
Update to version 2026.7.2
Update to version 2026.8.0
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse