CVE-2026-27154: Discourse has XSS when editing a malicious post
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, a user full name can be evaluated as raw HTML when the following settings are set: displaynameonposts => true; and prioritizeusernameinux => false. Editing a post of a malicious user would trigger an XSS. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patch the issue. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27154?
CVE-2026-27154 is classified as a moderate severity vulnerability due to its potential for XSS attacks.
How do I fix CVE-2026-27154?
To fix CVE-2026-27154, update Discourse to version 2025.12.2 or later, or 2026.1.1 or later, or 2026.2.0 or later.
What does CVE-2026-27154 expose users to?
CVE-2026-27154 exposes users to cross-site scripting (XSS) attacks when editing malicious posts.
Which versions of Discourse are affected by CVE-2026-27154?
CVE-2026-27154 affects Discourse versions prior to 2025.12.2, 2026.1.1, and 2026.2.0.
What settings trigger the vulnerability in CVE-2026-27154?
CVE-2026-27154 is triggered when 'display_name_on_posts' is set to true and 'prioritize_username_in_ux' is enabled.