Stored HTML Injection Vulnerability in Discourse Open-Source Discussion Platform
CVE-2026-91119
What is CVE-2026-91119?
Discourse is a popular open-source discussion platform that experienced a vulnerability prior to specific releases in 2026. This issue involved the interpolation of unsanitized free-form action_code_who values into mention-link href attributes within the topic small-action and nested-activity-log components. The failure to properly URL-encode these values allowed an attacker to terminate intended URL attributes and introduce malicious elements into the rendered markup. Although the mention text was displayed correctly, the unencoded path component made stored HTML injection possible when another user accessed the affected action or activity log. Updates in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0 address this vulnerability, enhancing platform security.
Affected Version(s)
discourse < 2026.8.0 < 2026.8.0
discourse >= 2026.7.0-latest, < 2026.7.2 < 2026.7.0-latest, 2026.7.2
discourse >= 2026.6.0-latest, < 2026.6.3 < 2026.6.0-latest, 2026.6.3