Discourse 是一个开源的讨论平台。在版本 2026.1.6、2026.5.2、2026.6.1 和 2026.7.0 之前,与私聊相关的 Discourse AI 审查项(reviewables)可能会出现在未参与该私聊的审核员的审查队列中。审查项可见性过滤机制未能将私聊相关审查项的限制应用于有权访问该私聊主题的受众,从而导致审核员能够查看本应保密的内容。根据可用的审查项操作权限,审核员还可能通过关闭相关主题或删除帖子等方式修改私聊内容。此漏洞的利用需要具备已认证的审核员账户以及一个已存在的、与私聊相关的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91122 | 8.7 HIGH | Discourse: Chat MessageBus delivers read-restricted messages to unauthorized users |
| CVE-2026-91123 | 7.2 HIGH | Discourse: Reject literal backslash path separators in iframe src traversal guard |
| CVE-2026-91133 | 6.5 MEDIUM | Discourse: Escape LIKE metacharacters in upload paths to prevent disclosure |
| CVE-2026-91119 | 6.4 MEDIUM | Discourse: Encode action_code_who in mention URLs |
| CVE-2026-91134 | 5.4 MEDIUM | Discourse: Block post iframes whose encoded userinfo bypasses the allowed_iframes allowlis |
| CVE-2026-91120 | 5.4 MEDIUM | Discourse: Stored HTML injection in video notification emails |
| CVE-2026-91121 | 5.0 MEDIUM | Discourse: Chat upload filenames rendered as raw HTML in excerpts |
| CVE-2026-91132 | 4.3 MEDIUM | Discourse: Wildcard iframe origin allowlist bypass via authority separators |
No comments yet