CVE-2026-55420

Published Jul 9, 2026

Last updated 3 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-55420 is an OS command injection vulnerability (CWE-78) in Discourse, an open-source discussion platform. Under certain non-default configurations, the processing of PDF uploads can be exploited to achieve remote code execution (RCE) on the host server. The issue stems from the improper neutralization of special elements in user input, which is inserted directly into a shell command. This allows the shell to interpret special characters in the input as executable commands, enabling unauthorized command execution. The vulnerability affects Discourse versions prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. To address the issue, developers released patches in these respective versions. The remediation includes hardening ImageMagick execution by implementing a default-deny security policy and transitioning allowed coders to an allowlist. Additionally, the experimental pdf-to-image logic in the `discourse-ai` plugin, which relied on processing PDFs via ImageMagick and Ghostscript, was removed.

Description
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-default configurations, processing of PDF uploads could be exploited to obtain RCE on the server. This issue is patched in 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Source
security-advisories@github.com
NVD status
Analyzed
Products
discourse

Risk scores

CVSS 3.1

Type
Primary
Base score
8.1
Impact score
5.9
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security-advisories@github.com
CWE-78

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

11

Configurations