Impact
An authenticated user can intercept private AI bot conversations through the reply stream, exposing sensitive messages and compromising confidentiality. The flaw is a classic information disclosure vulnerability (CWE‑200) that does not affect integrity or availability.
Affected Systems
Discourse for versions before 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. Users running these releases on any platform are susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid authenticated credentials and access to the AI bot feature, so the attack vector is likely an authenticated internal network context. There is no known public exploit at this time.
OpenCVE Enrichment