PT-2026-98204 · Discourse · Discourse

CVE-2026-91121

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2026.1.8 Discourse versions prior to 2026.6.3 Discourse versions prior to 2026.7.2 Discourse versions prior to 2026.8.0
Description Attacker-controlled upload filenames used in chat message excerpts are rendered as unescaped HTML. A user with the ability to upload files and send chat content can include markup in a filename that is subsequently interpreted by chat channel lists, chat summary emails, pinned message bars, reply previews, thread previews, and other excerpt renderers. This allows trusted-HTML injection, which can alter the rendered content of excerpts. While JavaScript execution was not demonstrated under default Content Security Policy (CSP) settings, sites that disable or relax the default CSP face increased exposure.
Recommendations Update to version 2026.1.8. Update to version 2026.6.3. Update to version 2026.7.2. Update to version 2026.8.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91121
GHSA-34RH-WJFV-65GQ

Affected Products

Discourse