5.0
MEDIUM CVSS 3.1
CVE-2026-91121
Discourse: Chat upload filenames rendered as raw HTML in excerpts
Description

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, attacker-controlled upload filenames used in chat message excerpts were rendered as unescaped HTML. A user able to upload a file and send chat content could place markup in a filename that was then interpreted by chat channel lists, chat summary emails, pinned message bars, reply previews, thread previews, and other excerpt renderers. The issue allowed trusted-HTML injection that altered rendered excerpt content, but JavaScript execution was not demonstrated with default Content Security Policy settings. The advisory states that no confidentiality, integrity, or availability impact was identified, while its structured scoring metadata separately assigns low integrity impact. Sites that disable or relax the default CSP have increased exposure. This issue is fixed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.

INFO

Published Date :

Sept. 24, 2026, 6:19 p.m.

Last Modified :

Sept. 24, 2026, 6:19 p.m.

Remotely Exploit :

Yes !
Affected Products

The following products are affected by CVE-2026-91121 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 134c704f-9b21-4f2e-91b3-4a467353bcc0
CVSS 3.1 MEDIUM MITRE-CVE
CVSS 3.1 MEDIUM [email protected]
Solution
Update Discourse to patched versions to prevent unescaped HTML in filenames from rendering as HTML.
  • Update Discourse to version 2026.1.8 or later.
  • Update Discourse to version 2026.6.3 or later.
  • Update Discourse to version 2026.7.2 or later.
  • Update Discourse to version 2026.8.0 or later.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-91121 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-91121 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-91121 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-91121 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by [email protected]

    Sep. 24, 2026

    Action Type Old Value New Value
    Added Description Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, attacker-controlled upload filenames used in chat message excerpts were rendered as unescaped HTML. A user able to upload a file and send chat content could place markup in a filename that was then interpreted by chat channel lists, chat summary emails, pinned message bars, reply previews, thread previews, and other excerpt renderers. The issue allowed trusted-HTML injection that altered rendered excerpt content, but JavaScript execution was not demonstrated with default Content Security Policy settings. The advisory states that no confidentiality, integrity, or availability impact was identified, while its structured scoring metadata separately assigns low integrity impact. Sites that disable or relax the default CSP have increased exposure. This issue is fixed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
    Added CWE CWE-79
    Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/91xxx/CVE-2026-91121.json">CVE-2026-91121</a>
    Added Reference https://github.com/discourse/discourse/commit/24cd7cc4c868f20e6037d67d801d60c3e289b278
    Added Reference https://github.com/discourse/discourse/commit/6e7a181909c34a059d2b0a6291335a363205b787
    Added Reference https://github.com/discourse/discourse/commit/9d6f5e64a1cb68e8208520e4209b361e14f7394b
    Added Reference https://github.com/discourse/discourse/commit/af197941f7613a3845cba21d217641c77c8ef836
    Added Reference https://github.com/discourse/discourse/pull/42882
    Added Reference https://github.com/discourse/discourse/security/advisories/GHSA-34rh-wjfv-65gq
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Sep. 24, 2026

    Action Type Old Value New Value
    Added SSVC {'id': 'CVE-2026-91121', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-09-24T17:27:35.450393Z'}
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.