CVE-2026-27740 identifies a cross-site scripting (XSS) vulnerability in Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2. This flaw allows a remote attacker to inject malicious payloads via prompt injection into the AI Large Language Model, which are then executed when a staff member views the unsanitized output in the Review Queue. Rated as Medium severity (CVSS 6.1), exploitation requires user interaction and can lead to low confidentiality and integrity impacts. As a workaround, AI triage automation scripts can be temporarily disabled. There is currently no evidence of active exploitation, nor are public exploit codes or significant community discussion available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2026.1.0, < 2026.1.2CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:* | ||
>= 2026.2.0, < 2026.2.1CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:* | ||
2026.3.0CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:2026.3.0:*:*:*:latest:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.