Impact
Discourse, an open‑source discussion platform, fails to fully sanitize SVG files that are uploaded or used as avatars. A malicious user can host a specially crafted SVG that contains executable JavaScript. When a user accesses the image through its URL, the embedded script executes in the victim’s browser, resulting in cross‑site scripting (CWE‑79).
Affected Systems
All Discourse installations running any release earlier than v2026.6.0, v2026.5.1, v2026.4.2, or v2026.1.5 are affected. The issue applies to both source‑built and packaged distributions that have not applied the latest patches.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity. The EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by uploading a malicious SVG or setting a malicious avatar. A victim must visit the image URL for the payload to take effect, and no privileged or network‑level access is required.
OpenCVE Enrichment