PT-2026-29315 · Discourse · Discourse-Subscriptions+1
Davidtaylorhq
·
Published
2026-03-31
·
Updated
2026-04-07
·
CVE-2026-33073
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Discourse versions 2026.1.0 through 2026.1.2, 2026.2.0 through 2026.2.1, and 2026.3.0 through 2026.3.0
Description
The discourse-subscriptions plugin leaks
stripe API keys across sites in a multisite cluster, potentially leading to the leakage of stripe-related information across sites within the same cluster.Recommendations
Update to Discourse version 2026.1.3 or later.
Update to Discourse version 2026.2.2 or later.
Update to Discourse version 2026.3.0 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse
Discourse-Subscriptions