Executive brief
Discourse is an open-source platform used for hosting online discussion forums and communities. A security vulnerability allows users with specific 'assign' permissions to inject malicious scripts into the platform's interface. If exploited, these scripts could execute in the browsers of other users, potentially leading to unauthorized actions or data theft within the forum environment.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Discourse due to improper neutralization of user-provided display names. When the 'prioritize_full_name_in_ux' site setting is enabled (which requires console access), the application fails to escape HTML in several assignment-related UI paths, such as assignment tags and topic-level menus. An attacker with 'assign' permissions can set a display name containing a malicious payload that executes in the context of any user viewing the affected topic. The vulnerability is triggered by the use of 'trustHTML()' without prior 'escapeExpression()' calls on user-controlled strings. Patches are available in versions 2026.1.3, 2026.2.2, and 2026.3.0.
Affected products
- Discourse Discourse 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, 2026.3.0-latest to before 2026.3.0
Timeline
- 2026-03-31: disclosed
- 2026-03-31: patched
- 2026-03-31: advisory