Description
Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged user could place crafted content in the moderation review queue that executed stored cross-site scripting when a moderator viewed it on a site with a modified or disabled default Content Security Policy. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
Published: 2026-08-10
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged user can submit crafted content into the moderation review queue of Discourse. When a moderator views an item in that queue on a site whose Content Security Policy is disabled or overly permissive, the stored script executes with the moderator’s browser context. This can allow the attacker to steal moderator credentials, deface the forum, or redirect users to malicious sites, thereby compromising the confidentiality and integrity of the discussion platform.

Affected Systems

Discourse, the open‑source discussion platform. Versions earlier than 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0 are affected.

Risk and Exploitability

The vulnerability has a CVSS score of 4.8, indicating moderate severity. No exploit probability score is available and the issue is not listed in CISA’s KEV catalog. The attack vector requires a low‑privileged user to submit content and a moderator to review it, and relies on a modified or missing CSP to succeed. Because the attack surface is limited to moderators and the vulnerability is only exploitable when CSP is weak, the overall risk to an organization is moderate but still requires remediation.

Generated by OpenCVE AI on August 10, 2026 at 17:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Discourse to any of the fixed releases: 2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0 or later.
  • If a patch is not immediately available, re‑enable or enforce a strict Content Security Policy that blocks inline script execution when viewing the moderation queue.
  • Restrict the ability of low‑privileged users to submit content into the moderation queue until the vulnerability is addressed.

Generated by OpenCVE AI on August 10, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged user could place crafted content in the moderation review queue that executed stored cross-site scripting when a moderator viewed it on a site with a modified or disabled default Content Security Policy. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
Title Discourse: Stored XSS in the moderation review queue
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-10T16:08:21.359Z

Reserved: 2026-08-10T13:48:09.545Z

Link: CVE-2026-72727

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T18:00:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')