CVE-2026-27570: Discourse Vulnerable to Stored XSS via Shared AI Conversation Onebox
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox method in the SharedAiConversation model renders the conversation title directly into HTML without proper sanitization. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. As a workaround, tighten access by changing the aibotpublicsharingallowedgroups site setting.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27570?
CVE-2026-27570 has a high severity due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2026-27570?
To fix CVE-2026-27570, upgrade to Discourse version 2026.3.0-latest.1, 2026.2.1, or 2026.1.2.
What versions of Discourse are affected by CVE-2026-27570?
CVE-2026-27570 affects versions of Discourse prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2.
What type of vulnerability is CVE-2026-27570?
CVE-2026-27570 is a stored XSS vulnerability that affects the Shared AI Conversation component in Discourse.
Can CVE-2026-27570 be exploited remotely?
Yes, CVE-2026-27570 can be exploited remotely by attackers to execute malicious scripts in user browsers.