Impact
This vulnerability allows a malicious user to embed arbitrary HTML or JavaScript in an actor’s display name, which is then rendered within post action descriptions without escaping. The stored payload is executed in the victim’s browser when the activity stream is viewed, potentially enabling credential theft or session hijacking. The weakness corresponds to CWE‑79, a classic cross‑site scripting flaw.
Affected Systems
Discourse, all versions prior to 2026.7.0, are affected. The issue was fixed in the 2026.7.0 release. No other vendors or product versions are currently impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, yet the flaw permits persistent client‑side code execution. Because the exploit requires only a crafted display name, the attack vector is essentially user input that is rendered without escaping; a malicious account holder could carry it out without additional access. EPSS data is unavailable and the vulnerability is not listed in CISA KEV, suggesting it has not yet been widely exploited, but the potential for widespread impact remains.
OpenCVE Enrichment