Discourse 是一个开源的讨论平台。在 2026.1.8、2026.6.3、2026.7.2 和 2026.8.0 版本之前,iframe 源(src)遍历保护机制在解码点段(dot segments)后,未将字面量反斜杠(literal backslashes)视为路径分隔符。因此,精心构造的 src 值可以通过 allowed_iframes 子路径检查,而浏览器在进行 URL 规范化时会将 iframe 移出预期的允许路径。结果可能导致 iframe 加载管理员未授权的内容。该问题已在版本 2026.1
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91122 | 8.7 HIGH | Discourse: Chat MessageBus delivers read-restricted messages to unauthorized users |
| CVE-2026-91133 | 6.5 MEDIUM | Discourse: Escape LIKE metacharacters in upload paths to prevent disclosure |
| CVE-2026-91119 | 6.4 MEDIUM | Discourse: Encode action_code_who in mention URLs |
| CVE-2026-91134 | 5.4 MEDIUM | Discourse: Block post iframes whose encoded userinfo bypasses the allowed_iframes allowlis |
| CVE-2026-91120 | 5.4 MEDIUM | Discourse: Stored HTML injection in video notification emails |
| CVE-2026-91121 | 5.0 MEDIUM | Discourse: Chat upload filenames rendered as raw HTML in excerpts |
| CVE-2026-91132 | 4.3 MEDIUM | Discourse: Wildcard iframe origin allowlist bypass via authority separators |
| CVE-2026-84302 | 4.2 MEDIUM | Discourse: Non-participant moderators can read, edit, and delete PM content through Discou |
No comments yet