PT-2026-98202 · Discourse · Discourse
CVE-2026-91119
·
Published
2026-09-24
·
Updated
2026-09-28
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to 2026.1.8
Discourse versions prior to 2026.6.3
Discourse versions prior to 2026.7.2
Discourse versions prior to 2026.8.0
Description
The topic small-action and nested-activity-log components interpolate the free-form
action code who value into mention-link href attributes without URL encoding. A display name containing quotes can terminate the intended URL attribute, allowing the injection of attacker-controlled elements into the rendered markup. While the visible mention text is escaped, the unencoded path component enables stored HTML injection when a user views the affected topic action or activity log.Recommendations
Update to version 2026.1.8
Update to version 2026.6.3
Update to version 2026.7.2
Update to version 2026.8.0
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse