HTML Injection Vulnerability in Discourse Open-Source Discussion Platform
CVE-2026-91120

5.4MEDIUM

Key Information:

Vendor

Discourse

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-91120?

Discourse, an open-source discussion platform, is susceptible to an HTML injection issue due to provider-controlled video titles in lazy video embeds. Prior to specific versions, an attacker could exploit this flaw by including markup in video titles within posts. When users with standard posting privileges create content featuring these embeds, the rendered notification emails and chat summaries may interpret the markup as HTML rather than plaintext. This risks injecting arbitrary HTML content, which may include event handlers, into emails viewed in HTML-capable clients. Although this vulnerability does not compromise a user's browser session or affect the forum interface itself, it poses significant risks related to email security. The issue has been addressed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.

Affected Version(s)

discourse < 2026.8.0 < 2026.8.0

discourse >= 2026.7.0-latest, < 2026.7.2 < 2026.7.0-latest, 2026.7.2

discourse >= 2026.6.0-latest, < 2026.6.3 < 2026.6.0-latest, 2026.6.3

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.