Unrated severityNVD Advisory· Published Feb 26, 2026· Updated Mar 3, 2026
DIscourse doesn't prevent whispers to leak in excerpts
CVE-2026-27162
Description
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, posts_nearby was checking topic access but then returning all posts regardless of type, including whispers that should only be visible to whisperers. Use Post.secured(guardian) to properly filter post types based on user permissions. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patch the issue. No known workarounds are available.
Affected products
1- Range: < 2025.12.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/discourse/discourse/security/advisories/GHSA-gffm-43j4-372wmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.