Stored HTML Injection Vulnerability in Discourse Open-Source Discussion Platform
CVE-2026-91119

6.4MEDIUM

Key Information:

Vendor

Discourse

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-91119?

Discourse is a popular open-source discussion platform that experienced a vulnerability prior to specific releases in 2026. This issue involved the interpolation of unsanitized free-form action_code_who values into mention-link href attributes within the topic small-action and nested-activity-log components. The failure to properly URL-encode these values allowed an attacker to terminate intended URL attributes and introduce malicious elements into the rendered markup. Although the mention text was displayed correctly, the unencoded path component made stored HTML injection possible when another user accessed the affected action or activity log. Updates in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0 address this vulnerability, enhancing platform security.

Affected Version(s)

discourse < 2026.8.0 < 2026.8.0

discourse >= 2026.7.0-latest, < 2026.7.2 < 2026.7.0-latest, 2026.7.2

discourse >= 2026.6.0-latest, < 2026.6.3 < 2026.6.0-latest, 2026.6.3

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.