Executive brief
Discourse, a popular open-source discussion and forum platform, is vulnerable to an open redirect flaw. An attacker can trick users into being redirected to a malicious website immediately after they log in to the forum. This can be used to conduct convincing phishing attacks to steal user credentials or distribute malware by making the malicious link appear to originate from a trusted forum domain.
Technical details
An open redirect vulnerability exists in Discourse's StaticController within the 'enter' action. The application reads the 'sso_destination_url' cookie and performs a redirect using 'allow_other_host: true' without validating if the destination URL is a trusted domain. While this cookie is intended for use with DiscourseConnect (SSO) flows, it is client-controlled. An attacker who can set cookies on the victim's browser (e.g., via XSS on a subdomain or cookie injection) can point this cookie to a malicious external site. When the victim subsequently hits the /login endpoint, they are redirected to the attacker's site post-authentication. The issue is patched in versions 2026.1.3, 2026.2.2, and 2026.3.0 by validating the cookie against configured SSO provider domains.
Affected products
- Discourse Discourse 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, 2026.3.0-latest to before 2026.3.0
Timeline
- 2026-03-31: disclosed
- 2026-03-31: patched
- 2026-03-31: advisory
References
- https://github.com/discourse/discourse/commit/080408b93d00305b51d71f63f755f43fa601884d
- https://github.com/discourse/discourse/security/advisories/GHSA-378j-ccw4-4fwh
- https://meta.discourse.org/t/using-discourse-as-a-sso-provider/32974
- https://meta.discourse.org/t/use-discourse-as-an-identity-provider-sso-discourseconnect/32974