Path Traversal Vulnerability in Discourse Discussion Platform
CVE-2026-91123
7.2HIGH
What is CVE-2026-91123?
The Discourse platform experienced a security vulnerability related to iframe src traversal. Prior to versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the system failed to correctly interpret literal backslashes as path separators after decoding dot segments. This oversight allowed an attacker to potentially bypass the 'allowed_iframes' subpath check, resulting in the loading of unauthorized content from outside the intended path. Updates have addressed this issue, enhancing the security of iframe handling within the platform.
Affected Version(s)
discourse < 2026.8.0 < 2026.8.0
discourse >= 2026.7.0-latest, < 2026.7.2 < 2026.7.0-latest, 2026.7.2
discourse >= 2026.6.0-latest, < 2026.6.3 < 2026.6.0-latest, 2026.6.3