Executive brief
Discourse is an open-source discussion platform used for community conversations and collaboration. A flaw in how the platform serializes group activity data allows users with permission to view group posts to access unpublished draft content they should not see, including draft titles, excerpts, and full post content. This leaks sensitive draft material that was intended to remain private until publication.
Technical details
An information disclosure vulnerability exists in Discourse's group post and group mentions API endpoints where shared-draft post entries are incorrectly included in serialized responses. The root cause is insufficient authorization checks in the post serialization logic that fails to filter out shared-draft content for users who lack explicit permission to view drafts. An authenticated user with permission to view group activity can exploit this by accessing the group posts or group mentions endpoints to retrieve draft topic titles, excerpts, and full post content. The vulnerability requires low privileges (group member access) and no user interaction, with network-based attack vector. Patches are available in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0; no workarounds are documented.
Affected products
- Discourse Discourse prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0
Timeline
- 2026-07-28: disclosed
- 2026-08-17: patched