Impact
The vulnerability originates from insufficient sanitization of URLs allowed in the default Codepen iframe configuration. An attacker can craft content that, when viewed by a user, injects HTML into the page and tricks the browser into navigating to a different URL. This can enable phishing or social engineering attacks against users, but does not provide arbitrary code execution on the server.
Affected Systems
Discourse is affected for all releases prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2. Users running those versions should verify their current build and apply updates accordingly.
Risk and Exploitability
The CVSS score of 4.1 indicates moderate severity, while the EPSS score of less than 1% shows a low likelihood of widespread exploitation at present. The vulnerability relies on a user viewing malicious content; no special privileges are needed. Native mitigations from Discourse are not listed in the CISA KEV catalog, reinforcing the need for a patch or configuration change.
OpenCVE Enrichment