Impact
Discourse, an open‑source discussion platform, has a stored cross‑site scripting flaw that occurs when a topic featured link is not properly normalized and escaped before being displayed in the topic list. A user who can set a featured link can embed malicious JavaScript, which will execute in the browsers of any visitor to the topic list if the platform’s default Content Security Policy protections are modified or disabled. This allows arbitrary script execution in a user’s browser context. The likely attack vector is that an authenticated user with permission to set or edit a featured link injects code, and the vulnerability is exploitable only when CSP protections are weakened or removed.
Affected Systems
Discourse Discourse platform. All releases before 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5 are vulnerable. The fix is available in these patched releases; upgrading to any of them removes the flaw. No other products or versions are mentioned as affected.
Risk and Exploitability
The CVSS score of 7.4 indicates a high risk that an attacker can execute arbitrary JavaScript in a victim’s browser, limited to the scope of that user’s session. The EPSS score of < 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, suggesting that no widespread exploitation has been observed yet. The flaw can be leveraged by those with editing privileges, particularly if the site’s default CSP has been weakened or disabled. Prompt patching reduces the possibility of malicious script execution.
OpenCVE Enrichment