Impact
Permalinks that target access‑restricted resources in Discourse redirect users to URLs containing the resource slug, even when the user lacks permission. The redirect Location header and the 404 page’s search box expose potentially sensitive information such as private topic titles or tags. The flaw is an information‑disclosure vulnerability (CWE‑200).
Affected Systems
Discourse, the open‑source discussion platform, is vulnerable in releases before 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0; any instance running those versions is impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity, while the EPSS score of less than 1% means exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. An attacker can craft a permalink or observe a legitimate link and trigger a redirect that exposes the slug, revealing sensitive identifiers to unauthenticated or unauthorized users. The attack vector is web‑based, requiring only the ability to access the permalink URL.
OpenCVE Enrichment