{"id":"BIT-discourse-2026-27570","summary":"Discourse Vulnerable to Stored XSS via Shared AI Conversation Onebox","details":"Discourse is an open-source discussion platform. Prior to versions 2026.3.0, 2026.2.1, and 2026.1.2, the onebox method in the SharedAiConversation model renders the conversation title directly into HTML without proper sanitization. Versions 2026.3.0, 2026.2.1, and 2026.1.2 contain a patch. As a workaround, tighten access by changing the `ai_bot_public_sharing_allowed_groups` site setting.","aliases":["CVE-2026-27570","GHSA-hfxw-89hw-vwmv"],"modified":"2026-09-08T08:46:31.649445525Z","published":"2026-03-27T07:09:54.665Z","database_specific":{"severity":"Medium","cpes":["cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*"]},"references":[{"type":"FIX","url":"https://github.com/discourse/discourse/commit/43a5a60b595f0120e6adfc131f2408508fe341f1"},{"type":"FIX","url":"https://github.com/discourse/discourse/commit/c14f8f52b7999328bd9f8665f2ecfa24dadc4bf1"},{"type":"FIX","url":"https://github.com/discourse/discourse/commit/f2aafa5c7467c94fcd4ebd36785a98e77ca088cc"},{"type":"ADVISORY","url":"https://github.com/discourse/discourse/security/advisories/GHSA-hfxw-89hw-vwmv"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27570"}],"affected":[{"package":{"name":"discourse","ecosystem":"Bitnami","purl":"pkg:bitnami/discourse"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2026.1.0"},{"fixed":"2026.1.2"},{"introduced":"2026.2.0"},{"fixed":"2026.2.1"},{"introduced":"2026.3.0"},{"fixed":"2026.3.0"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/discourse/BIT-discourse-2026-27570.json"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}],"schema_version":"1.9.0"}