Stored Cross-Origin Iframe Vulnerability in Discourse Platform
CVE-2026-91134
What is CVE-2026-91134?
The Discourse discussion platform had a vulnerability that allowed an attacker to exploit the post sanitizer mechanism. Prior to specific patched versions, this flaw permitted the injection of a stored cross-origin iframe, leading to unauthorized content rendering by bypassing the allowed_iframes prefix policy. The issue arose when the sanitizer validated a decoded form of the URL differently from the stored iframe source, allowing an attacker to persist an iframe within a user post, which could then render content from an attacker-controlled host. This vulnerability has been addressed in the updated versions of the Discourse platform.
Affected Version(s)
discourse < 2026.8.0 < 2026.8.0
discourse >= 2026.7.0-latest, < 2026.7.2 < 2026.7.0-latest, 2026.7.2
discourse >= 2026.6.0-latest, < 2026.6.3 < 2026.6.0-latest, 2026.6.3