{"id":"BIT-discourse-2026-72722","summary":"Discourse: Duplicate lookup reveals restricted topic titles through canonicalized URLs","details":"Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_from, TopicLink.ensure_entry_for, and TopicLink.duplicate_lookup do not consistently enforce Guardian.can_see? checks when processing internal links. An authenticated user can submit links to restricted topics, private messages, or hidden posts and receive canonicalized slugs or titles in the composer_messages duplicate_lookup response even though the targets are not visible to that user. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.","aliases":["CVE-2026-72722","GHSA-4fx9-5m29-83p4"],"modified":"2026-08-17T08:10:41.155430795Z","published":"2026-08-17T05:44:22.723Z","database_specific":{"severity":"Medium","cpes":["cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*"]},"references":[{"type":"WEB","url":"https://github.com/discourse/discourse/commit/45abd925e46e8be40d2d047bced26628f26e4e31"},{"type":"WEB","url":"https://github.com/discourse/discourse/commit/7d7ce546ac86e24a6512b321ace69fc52fe37bf4"},{"type":"WEB","url":"https://github.com/discourse/discourse/commit/836a251d54a1004fb1c463a7d299b933b176191f"},{"type":"WEB","url":"https://github.com/discourse/discourse/commit/e54ba27eacee0f14f315e510e287e7ac2e4bdb1a"},{"type":"WEB","url":"https://github.com/discourse/discourse/pull/42091"},{"type":"WEB","url":"https://github.com/discourse/discourse/pull/42092"},{"type":"WEB","url":"https://github.com/discourse/discourse/pull/42093"},{"type":"WEB","url":"https://github.com/discourse/discourse/pull/42094"},{"type":"WEB","url":"https://github.com/discourse/discourse/security/advisories/GHSA-4fx9-5m29-83p4"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72722"}],"affected":[{"package":{"name":"discourse","ecosystem":"Bitnami","purl":"pkg:bitnami/discourse"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2026.1.6"},{"introduced":"2026.5.0"},{"fixed":"2026.5.2"},{"introduced":"2026.6.0"},{"fixed":"2026.6.1"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/discourse/BIT-discourse-2026-72722.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}],"schema_version":"1.9.0"}