Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN932
_____________________________________________________________________

DATE                : 25/09/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S):  Systems running Discourse versions prior to 
                        2026.9.0, 2026.8.1, 2026.7.3, 2026.1.9.
  
=====================================================================
https://github.com/discourse/discourse/security/advisories/GHSA-f9jx-vv33-4282
https://github.com/discourse/discourse/security/advisories/GHSA-298h-xgw6-4pv3
_____________________________________________________________________

Stored oEmbed HTML injection via allowed iframe
High
davidtaylorhq published GHSA-f9jx-vv33-4282 

Software
Discourse

Affected versions
>= 0
>= 2026.8.0-latest
>= 2026.7.0-latest
>= 2026.1.0-latest

Patched versions
2026.9.0
2026.8.1
2026.7.3
2026.1.9


Description

Impact

A regular user with posting permissions could inject
attacker-controlled HTML and CSS into post content through the oEmbed
processing of a URL they post. This occurs when an oEmbed response
contains an iframe from an allowlisted origin (such as YouTube)
alongside unrelated sibling elements or style declarations — the
entire fragment was previously treated as trusted because the first
iframe matched the allowlist.

The vulnerability allowed stored injection of visual overlays or
other styled content that could mislead forum users into interacting
with fraudulent UI, effectively enabling phishing attacks against
other site visitors.

Successful exploitation requires:

    A standard posting account on the forum
    Control of a public webpage and its oEmbed response
    An iframe source from the configured allowlist (YouTube is a
default)

The impact is limited to content integrity — an attacker could
present misleading information but could not access restricted
data or disrupt service availability. No interaction with
Discourse's Content Security Policy is required.


Workarounds

There are no known workarounds that fully mitigate this
vulnerability without upgrading. Administrators can reduce
exposure by removing less-essential providers from the
iframe allowlist, though this may affect legitimate embeds.

Severity
High
7.7/ 10

CVSS v3 base metrics
Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
None
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

CVE ID
CVE-2026-91159

Weaknesses
No CWEs
_____________________________________________________________________


Media uploads remain publicly accessible after category permissions
are restricted
High
davidtaylorhq published GHSA-298h-xgw6-4pv3

Software
Discourse

Affected versions
>= 0
>= 2026.8.0-latest
>= 2026.7.0-latest
>= 2026.1.0-latest

Patched versions
2026.9.0
2026.8.1
2026.7.3
2026.1.9


Description

Impact

Sites using Discourse's secure uploads feature may expose media or
attachments that an administrator expects to be private. When a
category is changed from public to restricted (for example, by
limiting access to specific groups), uploads that were posted while
the category was public retain a flag that marks them as publicly
accessible. These uploads remain reachable by anonymous users at
their short URLs even after the category becomes read-restricted.
This affects all previously uploaded media in the affected
category, including content in topics that were deleted. The issue
occurs only on sites with secure uploads enabled, and only when a
previously public category is later restricted, or when category
permissions are changed during a bulk import operation.


Workarounds

Administrators who cannot upgrade immediately can mitigate the
exposure by downloading and re-uploading the affected media through
a restricted context, or by deleting the affected uploads from the
server. In cases where the affected uploads are no longer needed,
removing them from the Discourse storage location will prevent
anonymous access.


Severity
High
7.5/ 10

CVSS v3 base metrics
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE ID
CVE-2026-91157

Weaknesses
No CWEs


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




