Impact
A low‑privileged user can submit crafted content into the moderation review queue of Discourse. When a moderator views an item in that queue on a site whose Content Security Policy is disabled or overly permissive, the stored script executes with the moderator’s browser context. This can allow the attacker to steal moderator credentials, deface the forum, or redirect users to malicious sites, thereby compromising the confidentiality and integrity of the discussion platform.
Affected Systems
Discourse, the open‑source discussion platform. Versions earlier than 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0 are affected.
Risk and Exploitability
The vulnerability has a CVSS score of 4.8, indicating moderate severity. No exploit probability score is available and the issue is not listed in CISA’s KEV catalog. The attack vector requires a low‑privileged user to submit content and a moderator to review it, and relies on a modified or missing CSP to succeed. Because the attack surface is limited to moderators and the vulnerability is only exploitable when CSP is weak, the overall risk to an organization is moderate but still requires remediation.
OpenCVE Enrichment