What is CVE-2026-55674?
In prior versions of Discourse, an unauthenticated attacker could send a single request with a crafted `color_scheme_id` (or `dark_scheme_id`) cookie to inject arbitrary HTML into a page. Users should upgrade to version 2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0.
Azərbaycanca: Discourse-un əvvəlki versiyalarında autentifikasiya olunmamış hücumçu xüsusi hazırlanmış `color_scheme_id` (və ya `dark_scheme_id`) cookie ilə bir sorğu göndərərək səhifəyə ixtiyari HTML kodu yeridə bilər. Buna görə istifadəçilər 2026.1.6, 2026.5.2, 2026.6.1 və ya 2026.7.0 versiyalarına yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Does exploiting CVE-2026-55674 require the attacker to be authenticated?
No, an unauthenticated attacker can exploit this vulnerability by sending a single request with a crafted `color_scheme_id` (or `dark_scheme_id`) cookie.
Which versions should users upgrade to in order to fix CVE-2026-55674?
To fix this vulnerability, users should upgrade to Discourse version 2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.