CVE-2026-53960
Received Received - Intake

Information Disclosure in Discourse Q&A JSON-LD

Vulnerability report for CVE-2026-53960, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: GitHub, Inc.

Description

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post content was leaked as an excerpt in the publicly-served Q&A (QAPage) JSON-LD structured data, exposing it to any unauthenticated visitor and to search-engine crawlers. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-17
AI Q&A
2026-08-17
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
discourse discourse to 2026.1.6 (exc)
discourse discourse to 2026.5.2 (exc)
discourse discourse to 2026.6.1 (exc)
discourse discourse to 2026.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Discourse versions before 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0 leaked hidden or unviewable first-post content in JSON-LD structured data for Q&A pages. This exposed restricted content to unauthenticated visitors and search engines.

Detection Guidance

To detect this vulnerability, check if your Discourse instance is running a vulnerable version (2026.1.0-latest without patches). Inspect the QAPage JSON-LD structured data for exposed excerpts from hidden first-post content. Use curl to fetch the JSON-LD output from a Q&A page and review its contents for sensitive data.

Impact Analysis

Unauthenticated users and search engines could access sensitive or restricted first-post content, compromising confidentiality. The vulnerability required no privileges or user interaction to exploit.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, potentially violating GDPR (data protection) and HIPAA (health information privacy) by leaking restricted content.

Mitigation Strategies

Upgrade Discourse to a patched version: 2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0 or later. No other workarounds are available. Verify the fix by checking the JSON-LD output for exposed excerpts after upgrading.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53960. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart