CVE-2026-27166: Discourse vulnerable to HTML injection via prohibited iframe URLs
Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficient cleanup in the default Codepen allowed iframes value allows an attacker to trick a user into changing the URL of the main page. This issue has been fixed in versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2. To workaround this issue, remove Codepen from the list of allowed iframes.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27166?
CVE-2026-27166 is classified as a medium severity vulnerability due to its potential for HTML injection.
How do I fix CVE-2026-27166?
To fix CVE-2026-27166, upgrade Discourse to version 2026.3.0-latest.1 or later.
What impact does CVE-2026-27166 have on Discourse users?
CVE-2026-27166 allows attackers to manipulate iframe URLs, potentially leading to unauthorized content injection.
Which Discourse versions are affected by CVE-2026-27166?
Versions prior to Discourse 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 are affected by CVE-2026-27166.
Is CVE-2026-27166 easy to exploit?
Yes, CVE-2026-27166 can be easily exploited if users can be tricked into interacting with manipulated URLs.