Discourse
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*
- >= 2026.1.0-latest
- >= 2026.3.0-latest
- >= 2026.4.0-latest
A vulnerability in Discourse, an open-source discussion platform, allows outdated cached AI summaries to leak removed content to anonymous and unprivileged users who cannot regenerate summaries. This issue is present in Discourse versions prior to 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1.
Exploitation of this vulnerability can lead to the unauthorized disclosure of removed content to users who are not privileged or anonymous.
Users can upgrade to Discourse versions 2026.1.4, 2026.3.1, 2026.4.1, or 2026.5.0-latest.1. Alternatively, summary generation can be restricted by tightening the allowed groups on the summarization Personas.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.