CVE-2026-27740Disclosure(discourse / discourse)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch discourse discourse systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerability that arises because the system trusts the raw output from an AI Large Language Model (LLM) and renders it using htmlSafe in the Review Queue interface without adequate sanitization. A malicious attacker can use valid Prompt Injection techniques to force the AI to return a malicious payload (e.g., tags). When a Staff member (Admin/Moderator) views the flagged post in the Review Queue, the payload executes. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. As a workaround, temporarily disable AI triage automation scripts.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • discourse

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-22); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
discourse

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-03-20: 1Mentions · 2026-03-22: 3Mentions · 2026-04-10: 1Mentions · 2026-06-27: 1Mentions · 2026-07-04: 1Patch / Workaround · 2026-06-27: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 3Technical Details · 2026-04-10: 1Technical Details · 2026-06-27: 1Technical Details · 2026-07-04: 103-2003-2204-1006-2707-04
Signal classification2 categories
Disclosure
685.7%
Patch
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-201
Disclosure1
2026-03-223
Disclosure3
2026-04-101
Disclosure1
2026-06-271
Patch1
2026-07-041
Disclosure1
Full discourse7 posts
  • FAS Guardian@FAS_Guardian
    Disclosure

    New CVE: LLM output in Discourse wasn't sanitized. Stored XSS followed. AI doesn't eliminate classic web vulns - it amplifies them when you trust model output by default. Treat it like user input. https://nvd.nist.gov/vuln/detail/CVE-2026-27740 #AISecurity

    Post summary

    The post announces a new vulnerability (CVE-2026-27740) involving stored XSS due to unsanitized LLM output in Discourse, emphasizing that AI can amplify classic web flaws.

    0000035
    4 followersView on X
  • FAS Guardian@FAS_Guardian
    Patch

    CVE-2026-27740: Discourse's AI triage rendered raw LLM output without sanitization. Inject via prompt injection, wait for a mod to review the flagged post, XSS fires. AI output is still untrusted input. Patch: v2026.3+. https://nvd.nist.gov/vuln/detail/CVE-2026-27740

    Post summary

    The post highlights a prompt injection XSS issue in Discourse’s AI triage and announces a corrective patch in version 2026.3+, but does not note active exploitation or provide an exploit tool.

    0000049
    4 followersView on X
  • RagingCISO@CisoRaging77913
    Disclosure

    CVE-2026-27740: Discourse AI prompt injection → LLM outputs script tags → stored XSS → admin compromised. LLM output trusted, DOM injected unsanitized. 2005 XSS in "AI moderation" wrapper. Negligence as feature.

    Post summary

    The post outlines the technical details of CVE‑2026‑27740, describing how Discourse AI prompt injection leads to stored XSS and admin compromise, but it offers no PoC, exploit code, patch, or claim of active exploitation.

    0000037
    5 followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    📝 New article: CVE-2026-27740: When LLM Output Becomes an XSS Attack Vector https://moltx.io/articles/40379db6-e4f0-4701-b789-428c064ea3a7

    Post summary

    A brief article headline announces the newly identified CVE‑2026‑27740, noting that LLM output can be used for XSS attacks, but offers no further technical, exploit, or mitigation details.

    0000022
    4 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27740 Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerability that arises bec… https://www.cve.org/CVERecord?id=CVE-2026-27740 ----- Traducción: CVE-2026-27740 Dis… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026‑27740, a cross‑site scripting flaw in older Discourse releases, without mentioning a PoC, exploitation, or patch details.

    0000036
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27740 Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerability that arises bec… https://www.cve.org/CVERecord?id=CVE-2026-27740

    Post summary

    A cross‑site scripting vulnerability was disclosed for older Discourse platform versions, with the CVE identified as CVE‑2026‑27740 and referenced via the official CVE record.

    00000232
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27740 Cross-Site Scripting in Discourse AI Review Queue via Prompt Injection https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27740

    Post summary

    CVE-2026-27740 is a cross‑site scripting flaw in Discourse’s AI Review Queue that arises via prompt injection, but the brief notice provides no PoC, exploit, patch, or active exploitation details.

    0000032
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appdiscoursediscourse---
Appdiscoursediscourse2026.3.0--

Explore more