AI description
CVE-2026-55420 is an OS command injection vulnerability (CWE-78) in Discourse, an open-source discussion platform. Under certain non-default configurations, the processing of PDF uploads can be exploited to achieve remote code execution (RCE) on the host server. The issue stems from the improper neutralization of special elements in user input, which is inserted directly into a shell command. This allows the shell to interpret special characters in the input as executable commands, enabling unauthorized command execution. The vulnerability affects Discourse versions prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. To address the issue, developers released patches in these respective versions. The remediation includes hardening ImageMagick execution by implementing a default-deny security policy and transitioning allowed coders to an allowlist. Additionally, the experimental pdf-to-image logic in the `discourse-ai` plugin, which relied on processing PDFs via ImageMagick and Ghostscript, was removed.
- Description
- Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-default configurations, processing of PDF uploads could be exploited to obtain RCE on the server. This issue is patched in 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- discourse
CVSS 3.1
- Type
- Primary
- Base score
- 8.1
- Impact score
- 5.9
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- security-advisories@github.com
- CWE-78
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
11
Our research team discovered two vulnerabilities in Discourse: a pre-authentication cache poisoning to sitewide XSS (CVE-2026-55674), and an arbitrary file read (RCE) chaining a JPEG race condition with ImageMagick and Ghostscript (CVE-2026-55420). You can read more here: https:/
@assetnote
7 Oct 2026
6153 Impressions
30 Retweets
104 Likes
48 Bookmarks
2 Replies
2 Quotes
🚨*CVE* CVE-2026-55420 Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-default configurations, processing of PDF uplo… https://t.co/JdkAXSWLie ----- Traducción: CVE-2026-55420 Dis… https://t.co/utmtNg
@infoflowcloud
9 Jul 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E41661D7-5D61-44CF-BFEA-57C53057A46F",
"versionEndExcluding": "2026.1.5",
"versionStartIncluding": "2026.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E594AEEC-13D5-48EE-AE07-0C3C25FBBC72",
"versionEndExcluding": "2026.4.2",
"versionStartIncluding": "2026.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CD722A52-B00A-4548-92CA-807CEB0449B0",
"versionEndExcluding": "2026.5.1",
"versionStartIncluding": "2026.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:discourse:discourse:2026.6.0:*:*:*:latest:*:*:*",
"matchCriteriaId": "F2E7E180-2D99-484E-80A8-12F706ABDE65",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]