Impact
An authenticated user can pair a public channel identifier with a private thread identifier in a /onebox.json request, causing the system to resolve the chat thread independently of the channel before checking preview permissions. This bypasses privacy controls and returns the private thread message content, resulting in the unauthorized disclosure of private chat data. The weakness is consistent with an authorization bypass flaw.
Affected Systems
Discourse, the open‑source discussion platform, is affected in releases prior to 2026.1.6, 2026.5.2, 2026.6.1 and 2026.7.0. Users running any of these vulnerable versions may expose private chat messages to any authenticated account.
Risk and Exploitability
The CVSS score of 4.3 implies a low overall severity but the vulnerability can leak confidential conversation data. Exploitation requires a valid authenticated session and access to the onebox.json endpoint, so the attack vector is a remote authenticated network request. Because the EPSS score is not available and the issue is not listed in the CISA KEV catalog, the likelihood of mass exploitation is currently low. Nevertheless, the private information exposed may be sensitive, warranting prompt remediation. The flaw has been fixed in the subsequent releases that list the patched versions and is no longer present once upgraded.
OpenCVE Enrichment