Impact
Discourse permits secure uploads to be unintentionally exposed when the pull_hotlinked_images feature is used while the secure_uploads setting is enabled. If an attacker knows a secured upload URL, hotlinked image copying can retrieve the file and view its contents, leading to confidentiality loss and satisfying the CWE‑200 information‑exposure weakness.
Affected Systems
Discourse is vulnerable in releases prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. All earlier Discourse versions using the secure_uploads feature and pull_hotlinked_images can expose guarded uploads.
Risk and Exploitability
The CVSS base score evaluates the vulnerability at 6.3, indicating medium severity. The EPSS score of <1% shows a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation likely requires standard web access, suggesting a moderate likelihood of attack for environments with exposed Discourse instances.
OpenCVE Enrichment