CVE-2026-91134: Discourse
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the Discourse post sanitizer allowed a stored cross-origin iframe to bypass the allowed_iframes prefix policy when the iframe src contained encoded userinfo. The sanitizer validated a decoded form differently from the stored iframe src, allowing the browser to interpret an attacker-controlled host while the allowlist check accepted the encoded URL as an allowed prefix. An authenticated user with posting privileges could persist the iframe in a post and cause attacker-controlled cross-origin content to be rendered. This issue is fixed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.
Affected products
- Discourse Discourse: before 2026.8.0 (fixed in 2026.8.0); from 2026.7.0-latest, before 2026.7.2 (fixed in 2026.7.2); from 2026.6.0-latest, before 2026.6.3 (fixed in 2026.6.3); from 2026.1.0-latest, before 2026.1.8 (fixed in 2026.1.8)
Published 2026-09-24. Last modified 2026-09-29.