CVE-2026-91119: Discourse: Encode action_code_who in mention URLs
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the topic small-action and nested-activity-log components interpolated the free-form actioncodewho value into mention-link href attributes without URL encoding. A quote-bearing display name could terminate the intended URL attribute and inject attacker-controlled elements into the trusted rendered markup. Although the visible mention text was escaped, the unencoded path component allowed stored HTML injection when another user viewed the affected topic action or activity log. This issue is fixed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.1.8 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.6.3 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.7.2 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.8.0
Event History
Frequently Asked Questions
Who can exploit this issue and who is exposed?
An attacker needs privileges sufficient to control a free-form action_code_who value, reflected in topic small actions or nested activity logs. Users who view the affected topic action or activity log can be exposed to stored HTML injection.
Are default installations affected?
The provided information does not identify a configuration prerequisite. Any affected Discourse installation that renders attacker-controlled quote-bearing display names through the vulnerable components may be affected.
Which versions contain the fix?
The issue is fixed in Discourse versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0. Versions before those releases in their respective release lines are affected.