CVE-2026-59830
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Sep 21, 2026
Vendor
unknown
Description
Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-controlled display names before interpolating them into an HTML string passed to trustHTML. A user who could choose a crafted display name could persist markup in post action descriptions. Viewing the affected user activity streams could execute attacker-controlled script in another user's browser. This issue is fixed in version 2026.7.0.