CVE-2026-33395: Discourse has stored click‑based XSS via Graphviz SVG javascript: links
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the discourse-graphviz plugin contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious JavaScript code through DOT graph definitions. For instances with CSP disabled only. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. As a workaround, disable the graphviz plugin, upgrade to a patched version, or enable a content security policy.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33395?
CVE-2026-33395 has a medium severity rating due to its potential for stored XSS attacks on authenticated users.
How do I fix CVE-2026-33395?
To fix CVE-2026-33395, update the discourse-graphviz plugin to versions 2026.3.0-latest.1, 2026.2.1, or 2026.1.2 or later.
Who is affected by CVE-2026-33395?
CVE-2026-33395 affects users of the discourse-graphviz plugin on Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2.
What kind of attacks can CVE-2026-33395 allow?
CVE-2026-33395 can allow attackers to perform stored cross-site scripting (XSS) attacks on the affected Discourse platform.
Is CVE-2026-33395 present in all versions of Discourse?
No, CVE-2026-33395 is only present in versions of Discourse prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 that use the discourse-graphviz plugin.