PT-2026-98202 · Discourse · Discourse

CVE-2026-91119

·

Published

2026-09-24

·

Updated

2026-09-28

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2026.1.8 Discourse versions prior to 2026.6.3 Discourse versions prior to 2026.7.2 Discourse versions prior to 2026.8.0
Description The topic small-action and nested-activity-log components interpolate the free-form action code who value into mention-link href attributes without URL encoding. A display name containing quotes can terminate the intended URL attribute, allowing the injection of attacker-controlled elements into the rendered markup. While the visible mention text is escaped, the unencoded path component enables stored HTML injection when a user views the affected topic action or activity log.
Recommendations Update to version 2026.1.8 Update to version 2026.6.3 Update to version 2026.7.2 Update to version 2026.8.0

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91119
GHSA-PV3P-P3M9-V8V3

Affected Products

Discourse