CVE-2026-59830

medium

Description

Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-controlled display names before interpolating them into an HTML string passed to trustHTML. A user who could choose a crafted display name could persist markup in post action descriptions. Viewing the affected user activity streams could execute attacker-controlled script in another user's browser. This issue is fixed in version 2026.7.0.

References

https://github.com/discourse/discourse/security/advisories/GHSA-x6mf-p7cg-69rw

https://github.com/discourse/discourse/releases/tag/v2026.7.0

https://github.com/discourse/discourse/commit/dd786594ddd088657a7e6f9fefba5bd889965fe4

Details

Source: Mitre, NVD

Published: 2026-09-21

Updated: 2026-09-23

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.4

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00165