PT-2026-98203 · Discourse · Discourse

CVE-2026-91120

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2026.1.8 Discourse versions prior to 2026.6.3 Discourse versions prior to 2026.7.2 Discourse versions prior to 2026.8.0
Description Provider-controlled video titles in lazy video embeds can be reparsed as HTML during the generation of notification emails or chat summaries. A user with standard posting privileges can create a post using enabled providers such as YouTube, Vimeo, or TikTok. If the video title contains markup, the rendering path for emails and chat summaries inserts this markup into the output instead of treating it as plain text. This allows recipients using HTML-capable email clients to see injected content, which may include event handlers. This issue requires lazy video embeds to be enabled, which is the default configuration, but it does not affect the forum page or expose browser sessions.
Recommendations Update to version 2026.1.8. Update to version 2026.6.3. Update to version 2026.7.2. Update to version 2026.8.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91120
GHSA-H7CG-2VWW-M45C

Affected Products

Discourse