Executive brief
Discourse, a popular open-source discussion and forum platform, has addressed several security flaws in its chat and calendar plugins. These issues could allow unauthorized users to view private chat messages, permit restricted users to create new chat threads, or allow authors to restore deleted messages after their access was revoked. In some cases, private message content could be leaked to anonymous visitors through calendar event data, potentially exposing sensitive internal communications.
Technical details
Discourse chat and calendar plugins contain four distinct authorization and disclosure vulnerabilities. These include: 1) Missing authorization checks allowing read-only users to create chat threads; 2) Improper access control allowing authors to restore self-deleted messages after losing channel access; 3) Information disclosure where moderators reviewing flags are shown unrelated 'last_message' content from DMs; and 4) Data leakage in calendar event payloads that expose chat channel metadata and the most recent message to unauthorized or anonymous users. The vulnerabilities are primarily rooted in improper authorization (CWE-862) and sensitive information exposure (CWE-200). Exploitation is possible over the network without specialized privileges or user interaction. Patches are available in versions 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1.
Affected products
- Discourse Discourse 2026.1.0-latest to 2026.1.4, 2026.3.0-latest to 2026.3.1, 2026.4.0-latest to 2026.4.1
Timeline
- 2026-05-18: advisory: GitHub Security Advisory published
- 2026-06-12: disclosed: CVE published to NVD