PT-2026-98203 · Discourse · Discourse
CVE-2026-91120
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to 2026.1.8
Discourse versions prior to 2026.6.3
Discourse versions prior to 2026.7.2
Discourse versions prior to 2026.8.0
Description
Provider-controlled video titles in lazy video embeds can be reparsed as HTML during the generation of notification emails or chat summaries. A user with standard posting privileges can create a post using enabled providers such as YouTube, Vimeo, or TikTok. If the video title contains markup, the rendering path for emails and chat summaries inserts this markup into the output instead of treating it as plain text. This allows recipients using HTML-capable email clients to see injected content, which may include event handlers. This issue requires lazy video embeds to be enabled, which is the default configuration, but it does not affect the forum page or expose browser sessions.
Recommendations
Update to version 2026.1.8.
Update to version 2026.6.3.
Update to version 2026.7.2.
Update to version 2026.8.0.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse