CVE-2026-53962: Discourse: Insufficient SVG sanitization logic
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and user avatar handling could lead to cross-site scripting when a user visited specific URLs that are not normally part of community browsing. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.6.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.5.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.4.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.1.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53962?
The severity of CVE-2026-53962 is medium with a score of 5.4.
What type of vulnerability is CVE-2026-53962?
CVE-2026-53962 is a cross-site scripting (XSS) vulnerability due to insufficient SVG sanitization.
How does CVE-2026-53962 affect Discourse users?
CVE-2026-53962 can lead to cross-site scripting attacks when users visit specific URLs not commonly browsed.
How do I fix CVE-2026-53962?
To fix CVE-2026-53962, upgrade Discourse to versions 2026.6.0, 2026.5.1, 2026.4.2, or 2026.1.5.
When was CVE-2026-53962 published?
CVE-2026-53962 was published on July 9, 2026.