CVE-2021-39161: Cross-site scripting via category name in Discourse

Published Aug 26, 2021
·
Updated

Discourse is an open source platform for community discussion. In affected versions category names can be used for Cross-site scripting(XSS) attacks. This is mitigated by Discourse's default Content Security Policy and this vulnerability only affects sites which have modified or disabled or changed Discourse's default Content Security Policy have allowed for moderators to modify categories. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. Users are advised to ensure that the Content Security Policy is enabled, and has not been modified in a way which would make it more vulnerable to XSS attacks.

Affected Software

5 affected components
Discourse Discourse<2.7.8
Discourse Discourse=2.8.0-beta1
Discourse Discourse=2.8.0-beta2
Discourse Discourse=2.8.0-beta3
Discourse Discourse=2.8.0-beta4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Ensure Discourse’s default Content Security Policy is enabled and has not been modified/disabled/changed in a way that would make it more vulnerable to XSS attacks.

    Discourse Content Security Policy (Content-Security-Policy) = enabled (not modified to be more permissive for XSS)

Event History

Aug 26, 2021
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2021-39161?

CVE-2021-39161 has a moderate severity level due to its potential for Cross-site scripting (XSS) attacks.

2

How do I fix CVE-2021-39161?

To fix CVE-2021-39161, ensure that your Discourse installation is updated to version 2.7.8 or later.

3

Which versions of Discourse are affected by CVE-2021-39161?

CVE-2021-39161 affects Discourse versions prior to 2.7.8 and specific beta versions of 2.8.0.

4

What is the attack vector for CVE-2021-39161?

The attack vector for CVE-2021-39161 involves using category names to execute Cross-site scripting (XSS) attacks on vulnerable systems.

5

Is there a default protection against CVE-2021-39161?

Yes, Discourse includes a default Content Security Policy that mitigates the impact of CVE-2021-39161 unless it has been modified or disabled.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203