Security Bypass in Forem Community Software by Forem
CVE-2026-48780

8.2HIGH

Key Information:

Vendor

Forem

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2026-48780?

Forem, an open-source platform for building online communities, has a security bypass vulnerability that allows an attacker to circumvent domain allowlist or denylist controls through a specifically crafted email address. This vulnerability could enable unauthorized access to invite-only deployments of Forem, potentially compromising community integrity. The issue has been addressed in commit a2ab6d4, and in the interim, it's advisable for users to ensure that their SMTP servers and email service providers limit or reject malformed email addresses as an additional security measure.

Affected Version(s)

forem < a2ab6d4

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.