Local Date Format Rendering Vulnerability in Discourse Discussion Platform
CVE-2026-72729
2LOW
What is CVE-2026-72729?
The discourse-local-dates plugin in Discourse, an open-source discussion platform, is susceptible to a rendering flaw. When the default Content Security Policy (CSP) is either modified or disabled, the plugin can present specially crafted local-date format data as HTML, potentially compromising site security. This vulnerability has been rectified in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, highlighting the importance of maintaining updated versions to safeguard against such risks.
Affected Version(s)
discourse < 2026.1.6 < 2026.1.6
discourse >= 2026.5.0-latest, < 2026.5.2 < 2026.5.0-latest, 2026.5.2
discourse >= 2026.6.0-latest, < 2026.6.1 < 2026.6.0-latest, 2026.6.1