Discourse XSS via prompt injection in AI triage Review Queue (CVE-2026-27740)
Discourse versions before 2026.3.0-latest.1, 2026.2.1 and 2026.1.2 rendered raw LLM output with htmlSafe in the Review Queue, so an attacker could use prompt injection to make the AI return a malicious payload that executed when staff viewed a flagged post. Patched releases are available, with disabling AI triage automation scripts as a workaround.
Disclosed 19 March 2026 · Record updated 13 September 2026
Impact
Stored cross-site scripting executing in the browser of admins/moderators viewing flagged posts in the Review Queue.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-27740
