Impact
This vulnerability exists in Discourse’s handling of PDF uploads. A specially crafted PDF sent to an affected server system commands, giving an attacker the ability to run arbitrary code. The weakness, classified as CWE‑78, allows an attacker to bypass input controls and execute commands, potentially compromising confidentiality, integrity, and availability. The likely attack vector involves an attacker uploading a malicious PDF to the Discourse upload endpoint; this is inferred from the description because the vulnerability is tied to processing PDF uploads.
Affected Systems
Adversaries can target any Discourse installation running a pre‑2026.6.0, 2026.5.1, 2026.4.2, or 2026.1.5 build that has non‑default configurations enabling PDF upload capability. These affected versions are identified by the vendor as vulnerable until the patches in the listed maintenance releases are applied.
Risk and Exploitability
The CVSS score of 7.5 marks this flaw as high severity. The EPSS score is 0.0033 (<1%) indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalogue. An attacker must be able to upload files to the server, inferred from the nature of the vulnerability, which in many configurations is permitted to regular users or administrators. Once a malicious PDF is processed, command execution can be achieved with the privileges of the Discourse process.
OpenCVE Enrichment