Executive brief
Discourse is an open-source platform used for hosting online community discussions and chat. A security flaw in the chat search feature allows users to determine who belongs to specific private chat channels without having the proper authorization. This could lead to the exposure of private group memberships or the identification of participants in restricted discussions.
Technical details
An information disclosure vulnerability (CWE-200) exists in Discourse's chat component due to insufficient authorization checks in the user search functionality. Specifically, the 'excluded_memberships_channel_id' parameter in the chat search service failed to verify if the requesting user had permission to preview or access the specified channel. By manipulating search queries, an authenticated attacker can infer whether specific users are members of private or restricted chat channels. The vulnerability is exploited via network requests to the chat API. Patches have been released in versions 2026.1.3, 2026.2.2, and 2026.3.0 which implement proper 'guardian' checks to ensure channel visibility before returning search results.
Affected products
- Discourse Discourse 2026.1.0-latest to 2026.1.2, 2026.2.0-latest to 2026.2.1, 2026.3.0-latest before 2026.3.0
Timeline
- 2026-03-31: advisory: Vendor advisory published via GitHub
- 2026-03-31: patched: Fixes committed to main repository