{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "2026.8.0"
              },
              {
                "introduced": "2026.7.0-latest"
              },
              {
                "fixed": "2026.7.2"
              },
              {
                "introduced": "2026.6.0-latest"
              },
              {
                "fixed": "2026.6.3"
              },
              {
                "introduced": "2026.1.0-latest"
              },
              {
                "fixed": "2026.1.8"
              }
            ],
            "source": "AFFECTED_FIELD"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "fb9247e04a826ab8e4d91168b3c4c839ec40bccc"
            },
            {
              "introduced": "ded677e00beb0e9bae6e70b69582aecfb72b5477"
            },
            {
              "fixed": "3ab62a8397926ed934b667a5db06284c45b4c774"
            },
            {
              "introduced": "06d03da34c4ed09ea59f917f045ba250d2b6320d"
            },
            {
              "fixed": "777cb880553b517bc9ae502e935a160332e48b78"
            },
            {
              "introduced": "322d3c0ac6a8f133b3f82875e9dbbe310f638c1b"
            },
            {
              "fixed": "e808d0853e013abf90e648e53ebd606c49ccb19f"
            }
          ],
          "repo": "https://github.com/discourse/discourse",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-54vw-chv3-wjpv"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-20"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91134.json"
  },
  "details": "Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the Discourse post sanitizer allowed a stored cross-origin iframe to bypass the allowed_iframes prefix policy when the iframe src contained encoded userinfo. The sanitizer validated a decoded form differently from the stored iframe src, allowing the browser to interpret an attacker-controlled host while the allowlist check accepted the encoded URL as an allowed prefix. An authenticated user with posting privileges could persist the iframe in a post and cause attacker-controlled cross-origin content to be rendered. This issue is fixed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.",
  "id": "CVE-2026-91134",
  "modified": "2026-09-29T11:30:45.329059652Z",
  "published": "2026-09-24T16:51:34.057Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91134.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/discourse/discourse/security/advisories/GHSA-54vw-chv3-wjpv"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91134"
    },
    {
      "type": "FIX",
      "url": "https://github.com/discourse/discourse/commit/0a8015e6c7a5079981843721494d30c9a91f5415"
    },
    {
      "type": "FIX",
      "url": "https://github.com/discourse/discourse/commit/1304b0c04f87534053b0d574ae5a9b9ba13dd590"
    },
    {
      "type": "FIX",
      "url": "https://github.com/discourse/discourse/commit/bac7dd1201911851462483271b4567246fa1309d"
    },
    {
      "type": "FIX",
      "url": "https://github.com/discourse/discourse/commit/fed3a58c48412ce7207b72a4629ddbc44482cd64"
    },
    {
      "type": "FIX",
      "url": "https://github.com/discourse/discourse/pull/42882"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Discourse: Block post iframes whose encoded userinfo bypasses the allowed_iframes allowlist"
}