Junglewise Threat Intelligence

CVE-2026-32273: Discourse stored XSS in category description update API

CVE-2026-32273 · Severity: medium · CVSS 5.4 · Published 2026-03-31

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse is an open-source platform used by organizations to host online discussion forums and communities. A security flaw allows users with certain permissions to inject malicious scripts into category descriptions via the platform's programming interface (API). If an administrator or another user views the affected category, the script could run in their browser, potentially leading to unauthorized actions or data theft.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Discourse due to improper input sanitization when updating category descriptions through the API. While the 'create' endpoint was correctly sanitized, the 'update' endpoint failed to neutralize script-related HTML tags. An attacker with low-level privileges (sufficient to update a category) can inject malicious JavaScript into the description string. When a victim views the category, the payload executes in the context of their session. This can lead to session hijacking or unauthorized administrative actions. The issue is resolved in versions 2026.1.3, 2026.2.2, and 2026.3.0.

Affected products

  • Discourse Discourse >= 2026.1.0-latest, < 2026.1.3; >= 2026.2.0-latest, < 2026.2.2; >= 2026.3.0-latest, < 2026.3.0

Timeline

  • 2026-03-31: advisory: Vendor advisory published on GitHub
  • 2026-03-31: disclosed
  • 2026-03-31: patched

References

Related threats