FAS Guardian[verified]@FAS_GuardianDisclosure
The post announces a new vulnerability (CVE-2026-27740) involving stored XSS due to unsanitized LLM output in Discourse, emphasizing that AI can amplify classic web flaws.
FAS Guardian[verified]@FAS_GuardianPatch
The post highlights a prompt injection XSS issue in Discourse’s AI triage and announces a corrective patch in version 2026.3+, but does not note active exploitation or provide an exploit tool.
AI Security Guard[verified]@ai_security_10xDisclosure
A brief article headline announces the newly identified CVE‑2026‑27740, noting that LLM output can be used for XSS attacks, but offers no further technical, exploit, or mitigation details.
RagingCISO@CisoRaging77913Disclosure
The post outlines the technical details of CVE‑2026‑27740, describing how Discourse AI prompt injection leads to stored XSS and admin compromise, but it offers no PoC, exploit code, patch, or claim of active exploitation.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE-2026‑27740, a cross‑site scripting flaw in older Discourse releases, without mentioning a PoC, exploitation, or patch details.
CVE@CVEnewDisclosure
A cross‑site scripting vulnerability was disclosed for older Discourse platform versions, with the CVE identified as CVE‑2026‑27740 and referenced via the official CVE record.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
CVE-2026-27740 is a cross‑site scripting flaw in Discourse’s AI Review Queue that arises via prompt injection, but the brief notice provides no PoC, exploit, patch, or active exploitation details.