Security Bypass in Forem Community Software by Forem
CVE-2026-48780
8.2HIGH
What is CVE-2026-48780?
Forem, an open-source platform for building online communities, has a security bypass vulnerability that allows an attacker to circumvent domain allowlist or denylist controls through a specifically crafted email address. This vulnerability could enable unauthorized access to invite-only deployments of Forem, potentially compromising community integrity. The issue has been addressed in commit a2ab6d4, and in the interim, it's advisable for users to ensure that their SMTP servers and email service providers limit or reject malformed email addresses as an additional security measure.
Affected Version(s)
forem < a2ab6d4
