CVE-2021-41163

CRITICAL

Discourse - RCE

Title source: llm

Description

Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution. This resulted from a lack of validation in subscribe_url values. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. To workaround the issue without updating, requests with a path starting /webhooks/aws path could be blocked at an upstream proxy.

Exploits (2)

nomisec WORKING POC 3 stars
by ibrahmsql · poc
https://github.com/ibrahmsql/CVE-2021-41163
nomisec WORKING POC 2 stars
by ibrahmsql · poc
https://github.com/ibrahmsql/discourse-CVE-2021-41163

Scores

CVSS v3 10.0
EPSS 0.0365
EPSS Percentile 87.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-74
Status published
Products (2)
discourse/discourse 2.8.0 beta1 (6 CPE variants)
discourse/discourse < 2.7.9
Published Oct 20, 2021
Tracked Since Feb 18, 2026