CVE-2023-49099: Discourse

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when login is required. This vulnerability has been patched in 3.2.0.beta4 and 3.1.4.

Affected products

  • Discourse Discourse: before 3.1.4 (fixed in 3.1.4); version 3.2.0 only

Published 2024-01-12. Last modified 2026-06-17.