PT-2026-98204 · Discourse · Discourse
CVE-2026-91121
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to 2026.1.8
Discourse versions prior to 2026.6.3
Discourse versions prior to 2026.7.2
Discourse versions prior to 2026.8.0
Description
Attacker-controlled upload filenames used in chat message excerpts are rendered as unescaped HTML. A user with the ability to upload files and send chat content can include markup in a filename that is subsequently interpreted by chat channel lists, chat summary emails, pinned message bars, reply previews, thread previews, and other excerpt renderers. This allows trusted-HTML injection, which can alter the rendered content of excerpts. While JavaScript execution was not demonstrated under default Content Security Policy (CSP) settings, sites that disable or relax the default CSP face increased exposure.
Recommendations
Update to version 2026.1.8.
Update to version 2026.6.3.
Update to version 2026.7.2.
Update to version 2026.8.0.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse