Executive brief
Discourse, an open-source discussion platform, is affected by a vulnerability where AI-generated summaries of forum topics may contain content that has since been deleted or edited. This allows anonymous or low-privileged users to view sensitive information that was intended to be removed from public view. Organizations using the AI summarization feature should update to the latest version to ensure summaries are correctly invalidated when content changes.
Technical details
A vulnerability in Discourse's AI summarization feature (CWE-524, CWE-672) allows outdated cached summaries to persist after the underlying content has been modified or deleted. Because anonymous and unprivileged users lack the permissions to trigger a regeneration of these summaries, they are served the stale cached version containing the original, potentially sensitive, content. The issue is reachable over the network without authentication. It has been addressed in versions 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1 by ensuring summaries are properly updated or invalidated.
Affected products
- Discourse Discourse < 2026.1.4, < 2026.3.1, < 2026.4.1, < 2026.5.0-latest.1
Timeline
- 2026-05-18: advisory: GitHub Security Advisory GHSA-hjmg-2mww-vfvx published
- 2026-05-19: disclosed: NVD publication date