HTML Injection Vulnerability in Discourse Discussion Platform
CVE-2026-72720
What is CVE-2026-72720?
Discourse, an open-source discussion platform, is susceptible to an HTML injection flaw due to improper parsing of HTML in the PrettyText.format_for_email function. This vulnerability arises from reinterpreting cooked attribute values as markup, which may lead to potential security risks. Attackers can exploit this by embedding crafted Vimeo iframe sources or manipulating secure-upload URLs, causing unintended HTML rendering. Additionally, the vulnerability does not enforce strict validation for Vimeo-hosted iframes, allowing unauthorized iframes to be processed. Users are encouraged to update to versions 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1 to mitigate this risk.
Affected Version(s)
discourse < 2026.1.7 < 2026.1.7
discourse >= 2026.6.0-latest, < 2026.6.2 < 2026.6.0-latest, 2026.6.2
discourse >= 2026.7.0-latest, < 2026.7.1 < 2026.7.0-latest, 2026.7.1