Executive brief
Discourse is an open-source platform used for hosting online discussion forums and communities. A security vulnerability exists where a malicious user can name their two-factor authentication (2FA) method with a script that executes when an administrator attempts to manage or delete that user's account. If successful, this could allow an attacker to hijack administrative sessions, potentially leading to unauthorized access to sensitive community data or full control over the forum.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Discourse due to improper neutralization of input in the two-factor authentication (2FA) management interface. Specifically, the name assigned to a second-factor authentication method was not properly escaped when displayed within the delete confirmation dialog. An attacker with a low-privileged account can set a malicious payload as their 2FA device name. The vulnerability is triggered when an administrator impersonates the attacker's account and interacts with the 2FA deletion modal. This could lead to the execution of arbitrary JavaScript in the context of the administrator's session. The issue is resolved in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Affected products
- Discourse Discourse < 2026.1.5, < 2026.4.2, < 2026.5.1, < 2026.6.0
Timeline
- 2026-07-09: advisory: GitHub Security Advisory published
- 2026-07-09: disclosed: NVD publication date
References
- https://github.com/discourse/discourse/commit/40de62cddadc65c328a1028ab999f3fa94adbfed
- https://github.com/discourse/discourse/commit/529e17d4d570a48972e7cf64720e5dd1fdf23ca8
- https://github.com/discourse/discourse/commit/d92973e51a46cf6dd20c71e6068e6769b67eea5b
- https://github.com/discourse/discourse/commit/daea5214d833eacbdd3b1a78d99eb14e9cabd915
- https://github.com/discourse/discourse/releases/tag/v2026.1.5
- https://github.com/discourse/discourse/releases/tag/v2026.4.2
- https://github.com/discourse/discourse/releases/tag/v2026.5.1