Discourse 是一个开源讨论平台。在版本 2026.1.8、2026.6.3、2026.7.2 和 2026.8.0 之前,如果站点在 allowed_iframes 设置中使用了通配符模式,则可能接受一个构造的 iframe URL,其允许列表中的后缀出现在 URL 授权分隔符之后。通配符来源检查匹配的是允许的域名文本,而浏览器 URL 解析则选择了不同的、由攻击者控制的来源。具有发帖权限的用户可以通过帖子或 Onebox oEmbed 响应利用此漏洞,导致由攻击者控制的 iframe 在独立于允许列表域名
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91122 | 8.7 HIGH | Discourse: Chat MessageBus delivers read-restricted messages to unauthorized users |
| CVE-2026-91123 | 7.2 HIGH | Discourse: Reject literal backslash path separators in iframe src traversal guard |
| CVE-2026-91133 | 6.5 MEDIUM | Discourse: Escape LIKE metacharacters in upload paths to prevent disclosure |
| CVE-2026-91119 | 6.4 MEDIUM | Discourse: Encode action_code_who in mention URLs |
| CVE-2026-91134 | 5.4 MEDIUM | Discourse: Block post iframes whose encoded userinfo bypasses the allowed_iframes allowlis |
| CVE-2026-91120 | 5.4 MEDIUM | Discourse: Stored HTML injection in video notification emails |
| CVE-2026-91121 | 5.0 MEDIUM | Discourse: Chat upload filenames rendered as raw HTML in excerpts |
| CVE-2026-84302 | 4.2 MEDIUM | Discourse: Non-participant moderators can read, edit, and delete PM content through Discou |
No comments yet