CVE-2024-54142: Discourse Discourse-Ai

Critical severity, CVSS 9.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Discourse AI is a Discourse plugin which provides a number of AI features. When sharing Discourse AI Bot conversations into posts, if the conversation had HTML entities those could leak into the Discourse application when a user visited a post with a onebox to said conversation. This issue has been addressed in commit `92f122c`. Users are advised to update. Users unable to update may remove all groups from `ai bot public sharing allowed groups` site setting.

Affected products

  • Discourse Discourse-Ai: before 92f122c (fixed in 92f122c)

Published 2025-01-14. Last modified 2026-06-17.