CVE-2026-72730: Discourse: Stored XSS chat-transcript username unescaped in Rich Text Editor
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.1.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.5.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.6.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.7.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72730?
The severity of CVE-2026-72730 is high, with a CVSS score of 8.7.
How do I fix CVE-2026-72730?
To fix CVE-2026-72730, upgrade to versions 2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0 of Discourse.
What kind of vulnerability is CVE-2026-72730?
CVE-2026-72730 is a stored cross-site scripting (XSS) vulnerability in the Discourse Rich Text Editor.
What components are affected by CVE-2026-72730?
CVE-2026-72730 affects the chat-transcript feature in the Rich Text Editor of Discourse.
Can CVE-2026-72730 be exploited remotely?
Yes, CVE-2026-72730 can be exploited remotely due to the nature of the stored XSS.