CVE-2026-32273

MEDIUM5.4EPSS 0.04%

Discourse: XSS on category description update via API

發布日:2026/4/7修改日:2026/4/7
也稱為:GHSA-h2h4-767x-6pc8BIT-discourse-2026-32273

描述

Discourse is an open-source discussion platform. From versions 2026.1.0 to before 2026.1.3, and 2026.2.0 to before 2026.2.2, updating a category description via API is not sanitizing the description string, which can lead to XSS attacks. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

參考連結(3)