CVE-2026-91119 Details
Description
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the topic small-action and nested-activity-log components interpolated the free-form action_code_who value into mention-link href attributes without URL encoding. A quote-bearing display name could terminate the intended URL attribute and inject attacker-controlled elements into the trusted rendered markup. Although the visible mention text was escaped, the unencoded path component allowed stored HTML injection when another user viewed the affected topic action or activity log. This issue is fixed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.
A stored HTML injection vulnerability has been identified in Discourse, an open-source discussion platform, affecting versions prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0. The issue arises in the topic small-action and nested-activity-log components, where the free-form action_code_who value was interpolated into mention-link href attributes without proper URL encoding. This flaw allowed a quote-bearing display name to terminate the intended URL attribute and inject attacker-controlled elements into the rendered markup. While the visible mention text was escaped, the unencoded path component facilitated stored HTML injection when another user viewed the affected topic action or activity log.
Users can upgrade to Discourse versions 2026.1.8, 2026.6.3, 2026.7.2, or 2026.8.0 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Discourse | >= 2026.1.0-latest (semver) >= 2026.6.0-latest (semver) >= 2026.7.0-latest (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion