Junglewise Threat Intelligence

CVE-2026-45788: Discourse Information Disclosure via Secure Upload Hotlinking

CVE-2026-45788 · Severity: info · CVSS 6.3 · Published 2026-07-09

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse is an open-source platform used for hosting online discussion forums and communities. A security flaw allowed unauthorized users to access private images or files by "hotlinking" them into their own posts, even if they didn't have permission to view the original content. This could lead to the exposure of sensitive media intended for private categories or restricted groups.

Technical details

An information disclosure vulnerability exists in Discourse's 'Jobs::PullHotlinkedImages' component. When a user embeds an image tag pointing to a secure-uploads URL (such as one hosted on S3 for a private category), the background job would resolve the presigned URL and create a local copy attached to the new post without verifying if the author had permission to view the original upload. An attacker who knows or guesses a secure upload URL can bypass access controls by hotlinking it into a post they control. This issue has been patched by implementing a 'can_see_upload?' helper that validates the post author's permissions against the original upload's access control settings.

Affected products

  • Discourse Discourse < 2026.1.5, < 2026.4.2, < 2026.5.1, < 2026.6.0

Timeline

  • 2026-06-30: patched: Fixes released in various branches
  • 2026-07-09: advisory: CVE-2026-45788 published

References

Related threats