Junglewise Threat Intelligence

CVE-2026-53960: Discourse hidden first-post content leakage in Q&A JSON-LD schema

CVE-2026-53960 · Severity: medium · CVSS 5.3 · Published 2026-08-17

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse, a popular open-source community discussion platform, inadvertently exposed hidden or restricted forum posts in public JSON-LD metadata served to search engines and unauthenticated users. An attacker could read restricted content by parsing the page source or monitoring search engine indexes, bypassing the platform's access controls without authentication.

Technical details

The vulnerability is an information disclosure flaw in Discourse's Q&A (QAPage) JSON-LD structured data generation. Hidden or otherwise unviewable first-post excerpts were included in the publicly-served metadata, violating access controls. The attack vector is network-based with no authentication required; any unauthenticated visitor or search-engine crawler can access the leaked content by reading the JSON-LD schema embedded in page source. The flaw affects versions prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. The fix is available by upgrading to one of the patched versions.

Affected products

  • Discourse Discourse Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0

Timeline

  • 2026-07-28: disclosed
  • 2026-08-17: advisory
  • 2026: patched: Fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0

References

Related threats