HTML Injection Vulnerability in Discourse Discussion Platform
CVE-2026-72720

6.4MEDIUM

Key Information:

Vendor

Discourse

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72720?

Discourse, an open-source discussion platform, is susceptible to an HTML injection flaw due to improper parsing of HTML in the PrettyText.format_for_email function. This vulnerability arises from reinterpreting cooked attribute values as markup, which may lead to potential security risks. Attackers can exploit this by embedding crafted Vimeo iframe sources or manipulating secure-upload URLs, causing unintended HTML rendering. Additionally, the vulnerability does not enforce strict validation for Vimeo-hosted iframes, allowing unauthorized iframes to be processed. Users are encouraged to update to versions 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1 to mitigate this risk.

Affected Version(s)

discourse < 2026.1.7 < 2026.1.7

discourse >= 2026.6.0-latest, < 2026.6.2 < 2026.6.0-latest, 2026.6.2

discourse >= 2026.7.0-latest, < 2026.7.1 < 2026.7.0-latest, 2026.7.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.