Cross-Site Scripting Vulnerability in Discourse by Discourse
CVE-2026-55674

9.3CRITICAL

Key Information:

Vendor

Discourse

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-55674?

Discourse is an open-source discussion platform that, prior to the specified versions, was vulnerable to Cross-Site Scripting (XSS). An unauthenticated attacker could exploit this vulnerability by sending a single request with a manipulated 'color_scheme_id' or 'dark_scheme_id' cookie. This allowed the injection of arbitrary HTML into Discourse pages, as the cookie values were rendered into a color scheme tag without proper escaping. The lack of adequate security measures enabled the attacker to break out of the attribute and evade Discourse's nonce-based Content Security Policy, ultimately leading to arbitrary JavaScript execution in the browsers of unsuspecting visitors. This vulnerability has been addressed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

Affected Version(s)

discourse < 2026.1.6 < 2026.1.6

discourse >= 2026.5.0-latest, < 2026.5.2 < 2026.5.0-latest, 2026.5.2

discourse >= 2026.6.0-latest, < 2026.6.1 < 2026.6.0-latest, 2026.6.1

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.