AI description
CVE-2026-55674 is a vulnerability affecting Discourse, an open-source discussion platform, in versions prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. The flaw allows an unauthenticated attacker to inject arbitrary HTML into a Discourse page by sending a single request containing a crafted `color_scheme_id` or `dark_scheme_id` cookie. The vulnerability exists because the cookie value is rendered into a color scheme tag without proper escaping. This lack of sanitization enables an attacker to break out of the HTML attribute and inject a tag that bypasses Discourse's nonce-based Content Security Policy (CSP), resulting in arbitrary JavaScript execution in the browsers of visiting users. The issue has been addressed in the updated software releases.
- Description
- Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_scheme_id) cookie to inject arbitrary HTML into a Discourse page. Because the cookie value was rendered into a color scheme tag without escaping, the attacker could break out of the attribute and inject a tag that bypassed Discourse's nonce-based Content Security Policy, resulting in arbitrary JavaScript execution in visitors' browsers. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
- Source
- security-advisories@github.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 9.3
- Impact score
- 5.8
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-79
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
11