Path Traversal Vulnerability in Discourse Discussion Platform
CVE-2026-91123

7.2HIGH

Key Information:

Vendor

Discourse

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-91123?

The Discourse platform experienced a security vulnerability related to iframe src traversal. Prior to versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the system failed to correctly interpret literal backslashes as path separators after decoding dot segments. This oversight allowed an attacker to potentially bypass the 'allowed_iframes' subpath check, resulting in the loading of unauthorized content from outside the intended path. Updates have addressed this issue, enhancing the security of iframe handling within the platform.

Affected Version(s)

discourse < 2026.8.0 < 2026.8.0

discourse >= 2026.7.0-latest, < 2026.7.2 < 2026.7.0-latest, 2026.7.2

discourse >= 2026.6.0-latest, < 2026.6.3 < 2026.6.0-latest, 2026.6.3

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.