CVE-2026-91122

HIGHPre-NVD 8.78.7
EchelonGraph scoreLOW confidence

This high-severity CVE scores 8.7 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit-prediction score not yet available (the EPSS model rescores nightly; freshly-published CVEs typically appear within 48 hours). GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).

Triggered by: NVD CVSS baseline
Sources: secondary
8.7EG
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: —CVSS: 8.7Exploit: None knownExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placeholder component allowed crafted HTML to cause an attribute breakout and inject an attacker-controlled event handler. An authenticated user with default trust-level posting privileges could store the crafted placeholder in a post. When another user opened the post and clicked the video play overlay, the handler could execute arbitrary JavaScript in the viewer's session. Default Content Security Policy settings block inline event handlers, but instances with CSP disabled or relaxed could allow the script to read page content and make authenticated requests as the viewer. This issue is fixed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.

CVSS v3
8.7
EG Score
8.7(low)
EG Risk
39(Track)
EG Risk 39/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity87% × 45%
Exploitation0% × 40%
Automatability0% × 15%
Action: Routine — remediate on your standard cadence.
EPSS PROB
—
EPSS %ILE
—
KEV
Not listed

Published

September 24, 2026

Last Modified

September 24, 2026

Advisory Details (6)

Auto-updated Sep 24, 2026
Patch available. Sources: github, github_pr, github_commit.
github_commit

commit d7126af3264b (discourse/discourse)

Fix landed in discourse/discourse commit d7126af3264b — awaiting tagged release

https://github.com/discourse/discourse/commit/d7126af3264b672d2201d84c18a37cb8627424a8
github_commit

commit c3993e318e17 (discourse/discourse)

Fix landed in discourse/discourse commit c3993e318e17 — awaiting tagged release

https://github.com/discourse/discourse/commit/c3993e318e172389be5c98455177876f1dd87dda
github_commit

commit 5674b3e65948 (discourse/discourse)

Fix landed in discourse/discourse commit 5674b3e65948 — awaiting tagged release

https://github.com/discourse/discourse/commit/5674b3e6594825c28d2678e55057fd6802f11031
github_commit

commit 05d92b8749f6 (discourse/discourse)

Fix landed in discourse/discourse commit 05d92b8749f6 — awaiting tagged release

https://github.com/discourse/discourse/commit/05d92b8749f68d2626cbe65ec7adde7562a0283d
github_pr

Security fixes for main

Fix merged in discourse/discourse PR #42882 on 2026-08-25 — awaiting tagged release

https://github.com/discourse/discourse/pull/42882
github Patch Available

Stored XSS via video placeholder attribute breakout · Advisory · discourse/discourse · GitHub

https://github.com/discourse/discourse/security/advisories/GHSA-8m44-f6g9-7cg7

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Data Freshness Timeline

(refreshed 4× in last 7d / 4× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-09-24 18:35 UTCEG score recompute
  2. 2026-09-24 17:32 UTCEG score recompute
  3. 2026-09-24 17:02 UTCEG score recompute
  4. 2026-09-24 17:01 UTCMITRE cvelistV5first tracked

Frequently asked(4)

What is CVE-2026-91122?
CVE-2026-91122 is a high vulnerability published on September 24, 2026. Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placeholder component allowed crafted HTML to cause an attribute breakout and inject an attacker-controlled event handler. An authenticated user with default trust-level posting…
When was CVE-2026-91122 disclosed?
CVE-2026-91122 was first published in the National Vulnerability Database on September 24, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
What is the CVSS score of CVE-2026-91122?
CVE-2026-91122 has a CVSS v3 base score of 8.7 (NVD). The EG score is currently aggregating — additional source signals are being incorporated as they become available..
How do I remediate CVE-2026-91122?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-91122, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-91122

Explore →

Is Your Infrastructure Affected by CVE-2026-91122?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.