7.5

CVE-2026-45788

Discourse: Secure uploads exposed by hotlinked image copying

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlinked_images when an attacker knew the secured upload URL and the secure_uploads site setting was enabled. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DiscourseDiscourse Version >= 2026.1.0 < 2026.1.5
DiscourseDiscourse Version >= 2026.4.0 < 2026.4.2
DiscourseDiscourse Version >= 2026.5.0 < 2026.5.1
DiscourseDiscourse Version2026.6.0 SwEditionlatest
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.373
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
security-advisories@github.com 6.3 0 0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://github.com/discourse/discourse/releases/tag/v2026.1.5
Release Notes
https://github.com/discourse/discourse/releases/tag/v2026.4.2
Release Notes
https://github.com/discourse/discourse/releases/tag/v2026.5.1
Release Notes
https://github.com/discourse/discourse/releases/tag/v2026.6.0
Release Notes
https://github.com/discourse/discourse/security/advisories/GHSA-3876-w96v-8v38
Vendor Advisory
https://github.com/discourse/discourse/commit/5807c426880eadf248006e851604fc9284327ce5
Patch
https://github.com/discourse/discourse/commit/8b4a959b251a856a9c911fb9f2ac34fbc31a7471
Patch
https://github.com/discourse/discourse/commit/eff53af26367ae0dcb3a426954d233e8c7449f95
Patch
https://github.com/discourse/discourse/commit/fa74e0dec7341a858ab83a1977fa52629bced1aa
Patch