Impact
This vulnerability allows malicious users to embed arbitrary JavaScript within a chat-transcript username that is then rendered as HTML by Discourse's Rich Text Editor. The stored XSS flaw can execute in the browser of any user who views the affected chat transcript, leading to session hijacking, data theft, or defacement. The weakness is a classic input validation flaw described as CWE‑79.
Affected Systems
Discourse installations using the open-source platform before version 2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0 are affected. Updating to any of these patched releases removes the vulnerability.
Risk and Exploitability
The CVSS score of 8.7 reflects high severity. EPSS is unavailable, but the flaw can be exploited remotely through the web interface, as a malicious user can inject code that persists in stored data. The vulnerability is not listed in CISA KEV, but it is still technically exploitable as a web-based stored XSS incident.
OpenCVE Enrichment