CVE-2026-72720: Discourse: HTML injection in PrettyText.format_for_email from cooked-attribute reparsing
Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse has HTML injection in PrettyText.formatforemail because cooked attribute values are reparsed as markup. Crafted Vimeo iframe sources, secure-upload URLs or dimensions, and hashtag data-slug values can cause decoded attribute text to be reinterpreted as HTML. The vulnerable conversion also fails to strictly validate the Vimeo iframe host and path, allowing non-Vimeo allowlisted iframes to be converted. This issue is fixed in versions 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.1.7 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.6.2 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.7.1 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.8.0-latest.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72720?
CVE-2026-72720 has a medium severity score of 6.4.
How do I fix CVE-2026-72720?
To fix CVE-2026-72720, upgrade to Discourse versions 2026.1.7, 2026.6.2, 2026.7.1, or 2026.8.0-latest.1.
What type of vulnerability is CVE-2026-72720?
CVE-2026-72720 is classified as an HTML injection vulnerability related to cross-site scripting (XSS).
What are the affected versions of Discourse for CVE-2026-72720?
Affected versions for CVE-2026-72720 are prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1.
What can attackers do with CVE-2026-72720?
Attackers can exploit CVE-2026-72720 to inject malicious HTML content in emails generated by Discourse.