Executive brief
Discourse, a popular open-source discussion and forum platform, is vulnerable to a security flaw where malicious links can be used to run unauthorized code. An attacker with the ability to post links could potentially take over user accounts or steal sensitive information if the forum's default security settings have been weakened. This issue has been resolved in the latest software updates.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Discourse due to improper neutralization of input in the 'featured_link' field. The application failed to sufficiently normalize and escape these links before interpolating them into trusted HTML strings within the topic list. An attacker with low privileges (sufficient to set a featured link) can inject malicious JavaScript that executes in the context of other users' browsers. While Discourse's default Content Security Policy (CSP) provides significant mitigation, the vulnerability can be fully exploited if the CSP is modified or disabled. The fix involves improved normalization and escaping of the featured_link attribute, available in versions 2026.1.5, 2026.4.2, 2026.5.1, and 2026.6.0.
Affected products
- Discourse Discourse < 2026.1.5, < 2026.4.2, < 2026.5.1, < 2026.6.0
Timeline
- 2026-07-09: advisory
- 2026-06-30: patched: Release tags for fixed versions created on GitHub.
References
- https://github.com/discourse/discourse/commit/1bce8881e4253d9bbab56f011a12ef899b926b59
- https://github.com/discourse/discourse/commit/6679d9a5083488bae10c2adbb345c481c583242c
- https://github.com/discourse/discourse/commit/6828aee9b15c2655d63b515ac919830bd540ff83
- https://github.com/discourse/discourse/commit/c9b9405f5bd0bf0269e505e28e3aad388d7657c5
- https://github.com/discourse/discourse/releases/tag/v2026.1.5
- https://github.com/discourse/discourse/releases/tag/v2026.4.2
- https://github.com/discourse/discourse/releases/tag/v2026.5.1