CVE-2026-32607

MEDIUM

Discourse: Stored XSS via unescaped assignee name

Title source: cna

Description

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, when the hidden prioritize_full_name_in_ux site setting is enabled (defaults to false, requires console access to change), user and group display names are rendered without HTML escaping in several assignment-related UI paths. This allows users with assign permission to inject arbitrary HTML/JavaScript that executes in the browser of any user viewing an affected topic. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.

Scores

CVSS v3 5.4
EPSS 0.0003
EPSS Percentile 8.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (5)
discourse/discourse 2026.3.0 (2 CPE variants)
discourse/discourse 2026.1.0 - 2026.1.3
discourse/discourse >= 2026.1.0-latest, < 2026.1.3
discourse/discourse >= 2026.2.0-latest, < 2026.2.2
discourse/discourse >= 2026.3.0-latest, < 2026.3.0
Published Mar 31, 2026
Tracked Since Mar 31, 2026