CVE-2026-72728: Discourse: Onebox iframe origin allowlist enforces URL authority boundary
Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox allowlist and embedded malicious content in a site. This issue is fixed in versions 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.1.7 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.6.2 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.7.1 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.8.0-latest.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72728?
The severity of CVE-2026-72728 is medium with a score of 6.3.
How do I fix CVE-2026-72728?
CVE-2026-72728 can be fixed by upgrading to versions 2026.1.7, 2026.6.2, 2026.7.1, or 2026.8.0-latest.1 of Discourse.
What does CVE-2026-72728 affect?
CVE-2026-72728 affects the Onebox feature in Discourse, which can allow malicious content to be embedded.
Who is impacted by CVE-2026-72728?
Any authenticated user on a Discourse platform prior to the vulnerability fix could potentially exploit CVE-2026-72728.
What component of Discourse is involved in CVE-2026-72728?
CVE-2026-72728 involves the Onebox iframe origin allowlist feature in Discourse.