PT-2026-29303 · Discourse · Discourse
Davidtaylorhq
·
Published
2026-03-31
·
Updated
2026-04-07
·
CVE-2026-32113
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Discourse versions 2026.1.0 through 2026.1.2, 2026.2.0 through 2026.2.1, and 2026.3.0
Description
The
StaticController's enter action does not validate the sso destination url cookie before redirecting to it with allow other host: true. This cookie, normally set during legitimate DiscourseConnect Provider flows, is client-controlled and can be manipulated by attackers.Recommendations
Update to Discourse version 2026.1.3 or later.
Update to Discourse version 2026.2.2 or later.
Update to Discourse version 2026.3.0 or later.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse