VYPR
Medium severity4.1NVD Advisory· Published Mar 19, 2026· Updated Jun 17, 2026

CVE-2026-27166

CVE-2026-27166

Description

Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficient cleanup in the default Codepen allowed iframes value allows an attacker to trick a user into changing the URL of the main page. This issue has been fixed in versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2. To workaround this issue, remove Codepen from the list of allowed iframes.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*range: <2026.3.0
    • cpe:2.3:a:discourse:discourse:2026.3.0:*:*:*:latest:*:*:*
    • (no CPE)range: <2026.3.0-latest.1, <2026.2.1, <2026.1.2
    • (no CPE)range: < 2026.3.0-latest.1
  • osv-coords
    Range: >= 2026.1.0, < 2026.1.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.