Junglewise Threat Intelligence

CVE-2026-72730: Discourse stored XSS in Rich Text Editor chat transcript username

CVE-2026-72730 · Severity: high · CVSS 8.7 · Published 2026-08-10

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse is an open-source discussion platform used for online communities and team collaboration. A vulnerability in the Rich Text Editor failed to escape usernames in chat transcripts, allowing attackers to inject malicious HTML and JavaScript code. When users view affected chat transcripts, the injected code executes in their browsers, potentially enabling account theft, session hijacking, or data theft from community members.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Discourse's Rich Text Editor component. The vulnerable code fails to properly HTML-escape usernames when rendering chat-transcript content, allowing an attacker to embed malicious JavaScript in a username. When other users view the chat transcript through the Rich Text Editor, the unescaped HTML is rendered and the JavaScript executes in their browser context. The vulnerability requires an attacker to have the ability to set or control a username in a chat message. Patches are available in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

Affected products

  • Discourse Discourse prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0

Timeline

  • 2026-08-10: disclosed
  • 2026-01-06: patched: version 2026.1.6
  • 2026-05-02: patched: version 2026.5.2
  • 2026-06-01: patched: version 2026.6.1
  • 2026-07-00: patched: version 2026.7.0

References

Related threats