Vulnerability Description
Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox allowlist and embedded malicious content in a site. This issue is fixed in versions 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/discourse/discourse/commit/92eec47e8b477cb8b4ccdb237e26dc1ba8
- https://github.com/discourse/discourse/security/advisories/GHSA-qp9j-3v7r-wrvr
FAQ
What is CVE-2026-72728?
CVE-2026-72728 is a vulnerability with a CVSS score of 6.3 (MEDIUM). Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox allowlist and embedded malicious content in a site...
How severe is CVE-2026-72728?
CVE-2026-72728 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-72728?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.