6.5

CVE-2026-72726

Discourse: Unauthorized eavesdropping on private AI bot conversations.

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated user could eavesdrop on private AI bot conversations through the AI bot reply stream. The issue is fixed in 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerdiscourse
Produkt discourse
Version < 2026.1.6
Status affected
Version >= 2026.5.0, < 2026.5.2
Status affected
Version >= 2026.6.0, < 2026.6.1
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.258
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://github.com/discourse/discourse/security/advisories/GHSA-gw88-2jw8-jf2h
https://github.com/discourse/discourse/commit/01faa889830f56e02fba2f6c1731811d319c5e81
https://github.com/discourse/discourse/commit/1fb2026eb8004dfeb12553014cc534dfd8083fbc
https://github.com/discourse/discourse/commit/9247666f8359f3cf214b8aea3d396e8a8237ed38
https://github.com/discourse/discourse/commit/b56b98232aa4dad4a30500a65e31db0c9080c8f5