Unrated severityNVD Advisory· Published Mar 17, 2023· Updated Feb 25, 2025
Discourse chat messages susceptible to Cross-site Scripting through chat excerpts
CVE-2023-26040
Description
Discourse is an open-source discussion platform. Between versions 3.1.0.beta2 and 3.1.0.beta3 of the tests-passed branch, editing or responding to a chat message containing malicious content could lead to a cross-site scripting attack. This issue is patched in version 3.1.0.beta3 of the tests-passed branch. There are no known workarounds.
Affected products
1- Range: tests-passed > 3.1.0.beta2, < 3.1.0.beta3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/discourse/discourse/commit/a373bf2a01488c206e7feb28a9d2361b22ce6e70mitrex_refsource_MISC
- github.com/discourse/discourse/security/advisories/GHSA-ccfc-qpmp-gq87mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.