CVE-2026-32951

MEDIUM4.3EPSS 0.05%

Discourse: Authorization bypass in oneboxer via user-controlled category id

Published: 4/7/2026Modified: 4/7/2026
Also known as:GHSA-v93g-8f4f-4rgmBIT-discourse-2026-32951

Description

Discourse is an open-source discussion platform. From versions 2026.1.0 to before 2026.1.3, and 2026.2.0 to before 2026.2.2, an authenticated user can obtain shared draft topic titles by sending an inline onebox request with a category_id parameter matching the shared drafts category. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References (3)