Executive brief
Discourse is an open-source community discussion platform used to host forums and conversations. A low-privileged user can inject malicious code into the moderation review queue that executes when moderators view it, but only on sites that have disabled or modified Discourse's standard security policy. This could allow attackers to steal moderator session tokens or perform actions as a moderator without proper authorization.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in Discourse's moderation review queue. A low-privileged user can craft and submit content containing JavaScript that persists in the moderation queue. When a moderator later views the queued content, the JavaScript executes in the moderator's browser session. The vulnerability is contingent on the site having modified or disabled Discourse's default Content Security Policy (CSP), which normally prevents inline script execution. The attack requires the attacker to have user account privileges and the moderator to view the crafted content. Patches are available in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
Affected products
- Discourse Discourse prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0
Timeline
- 2026-07-28: disclosed
- 2026-07-28: patched