{"id":"CVE-2026-59830","published":"2026-09-21T22:16:57.353","lastModified":"2026-09-21T22:16:57.353","description":"Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-controlled display names before interpolating them into an HTML string passed to trustHTML. A user who could choose a crafted display name could persist markup in post action descriptions. Viewing the affected user activity streams could execute attacker-controlled script in another user's browser. This issue is fixed in version 2026.7.0.","cvssScore":5.4,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://github.com/discourse/discourse/commit/dd786594ddd088657a7e6f9fefba5bd889965fe4","tags":[]},{"url":"https://github.com/discourse/discourse/releases/tag/v2026.7.0","tags":[]},{"url":"https://github.com/discourse/discourse/security/advisories/GHSA-x6mf-p7cg-69rw","tags":[]}],"exploitRefs":[{"url":"https://github.com/discourse/discourse/commit/dd786594ddd088657a7e6f9fefba5bd889965fe4","tags":[]},{"url":"https://github.com/discourse/discourse/releases/tag/v2026.7.0","tags":[]},{"url":"https://github.com/discourse/discourse/security/advisories/GHSA-x6mf-p7cg-69rw","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows user-controlled display names to contain HTML, enabling script injection in post actions. This can lead to cross-site scripting (XSS) attacks.","exploitability":"Exploitation requires a user to choose a crafted display name and view another user's activity stream; not easily automated.","blast_radius":"Real-world impact could include unauthorized script execution in users' browsers, potentially leading to data theft or further exploitation.","remediation":"Update to Discourse version 2026.7.0 immediately to mitigate the vulnerability.","tags":["xss","html-injection","discourse","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:27:02.104Z"}}