Junglewise Threat Intelligence

CVE-2026-72728: Discourse Onebox allowlist bypass

CVE-2026-72728 · Severity: medium · CVSS 6.3 · Published 2026-08-10

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse is an open-source discussion platform used for community discussions and forums. An authenticated user could craft malicious URLs to bypass content filtering controls and embed unauthorized content (such as malicious scripts or phishing links) into forum posts, potentially affecting all site visitors who view the affected content.

Technical details

The vulnerability exists in Discourse's Onebox feature, which embeds previews of linked content. The allowlist validation for iframe origins used an overly permissive regular expression pattern that failed to properly enforce URL authority boundaries. An authenticated attacker could submit specially-formed URLs that matched the allowlist regex but contained malicious subdomains or path components, bypassing the security controls intended to prevent embedding of arbitrary third-party content. The fix changes the wildcard matching pattern from `\S*` (any non-whitespace) to `[^/?#]*` (characters excluding path/query/fragment delimiters), properly enforcing origin boundary validation. Patches are available in versions 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1.

Affected products

  • Discourse Discourse < 2026.1.7, >= 2026.6.0 and < 2026.6.2, >= 2026.7.0 and < 2026.7.1

Timeline

  • 2026-07-31: disclosed
  • 2026-07-31: patched: Fix committed on 2026-07-31
  • 2026-08-10: advisory: CVE-2026-72728 published

References

Related threats