Security Vulnerability in Discourse Open-Source Discussion Platform
CVE-2026-72728

6.3MEDIUM

Key Information:

Vendor

Discourse

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72728?

Discourse, a popular open-source discussion platform, was identified to have a vulnerability that allowed authenticated users to manipulate specially crafted URLs. This bypassed the Onebox allowlist, enabling the embedding of potentially harmful content on user sites. The issue has been resolved in versions 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, ensuring enhanced security for users.

Affected Version(s)

discourse < 2026.1.7 < 2026.1.7

discourse >= 2026.6.0-latest, < 2026.6.2 < 2026.6.0-latest, 2026.6.2

discourse >= 2026.7.0-latest, < 2026.7.1 < 2026.7.0-latest, 2026.7.1

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.