HTML Injection Vulnerability in Discourse Open-Source Discussion Platform
CVE-2026-91120
What is CVE-2026-91120?
Discourse, an open-source discussion platform, is susceptible to an HTML injection issue due to provider-controlled video titles in lazy video embeds. Prior to specific versions, an attacker could exploit this flaw by including markup in video titles within posts. When users with standard posting privileges create content featuring these embeds, the rendered notification emails and chat summaries may interpret the markup as HTML rather than plaintext. This risks injecting arbitrary HTML content, which may include event handlers, into emails viewed in HTML-capable clients. Although this vulnerability does not compromise a user's browser session or affect the forum interface itself, it poses significant risks related to email security. The issue has been addressed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.
Affected Version(s)
discourse < 2026.8.0 < 2026.8.0
discourse >= 2026.7.0-latest, < 2026.7.2 < 2026.7.0-latest, 2026.7.2
discourse >= 2026.6.0-latest, < 2026.6.3 < 2026.6.0-latest, 2026.6.3