Junglewise Threat Intelligence

CVE-2026-44785: Discourse AI information disclosure in Explain helper

CVE-2026-44785 · Severity: medium · CVSS 4.3 · Published 2026-06-12

Vendors: Discourse.

Executive brief

Discourse is an open-source platform used for hosting online discussion forums and communities. A security flaw in the platform's AI "Explain" feature allows logged-in users to view the private content of hidden posts. By using the AI tool on a public reply to a hidden message, an attacker can trick the system into revealing the original restricted text, potentially exposing sensitive or private conversations.

Technical details

An information disclosure vulnerability exists in the Discourse AI "explain" helper due to improper authorization checks. The component validates the 'can_see?' permission for the specific post being explained but fails to perform the same check for the 'reply_to_post' (the parent post). An authenticated attacker with access to the AI helper can invoke the "Explain" feature on a public reply to a hidden post, causing the AI to retrieve and display the raw contents of the restricted parent post. This issue is tracked as CWE-200 and has been patched in versions 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1.

Affected products

  • Discourse Discourse AI 2026.1.0-latest to 2026.1.4, 2026.3.0-latest to 2026.3.1, 2026.4.0-latest to 2026.4.1

Timeline

  • 2026-05-18: advisory: GitHub Security Advisory published by Discourse
  • 2026-06-12: disclosed: CVE published to NVD

References