CVE-2026-91120: Discourse: Stored HTML injection in video notification emails
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, provider-controlled video titles in lazy video embeds could be reparsed as HTML when Discourse generated notification emails or chat summaries. A user with standard posting privileges could create a post for an enabled YouTube, Vimeo, or TikTok provider whose title contained markup, and the email and chat-summary rendering path would place that markup into the output instead of treating it solely as text. Recipients using HTML-capable email clients could see injected content, potentially including event handlers, but the issue did not directly expose a Discourse browser session or affect the forum page itself. Lazy video embeds must be enabled, which is the default configuration. This issue is fixed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.1.8 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.6.3 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.7.2 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.8.0
Event History
Frequently Asked Questions
Who can exploit this issue and who is exposed?
Any user with standard posting privileges can create the malicious video embed. Exposure is limited to recipients of notification emails or chat summaries who use HTML-capable email clients; the forum page itself is not affected.
Is the default Discourse configuration affected?
Yes. Exploitation requires lazy video embeds to be enabled, and this is the default configuration. The affected providers are YouTube, Vimeo, and TikTok.
What can be done before upgrading?
Disable lazy video embeds to prevent the affected rendering path from being used. Upgrading to 2026.1.8, 2026.6.3, 2026.7.2, or 2026.8.0 fixes the issue.
Does this compromise a recipient's Discourse session or alter forum content?
No. The issue does not directly expose a Discourse browser session and does not affect the forum page itself; it affects HTML output in notification emails and chat summaries.