Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-default configurations, processing of PDF uploads could be exploited to obtain RCE on the server. This issue is patched in 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
References
| Link | Resource |
|---|---|
| https://github.com/discourse/discourse/commit/ca5a7e06167561928556afa2f237d67e459c6914 | Patch |
| https://github.com/discourse/discourse/releases/tag/v2026.1.5 | Release Notes |
| https://github.com/discourse/discourse/releases/tag/v2026.4.2 | Release Notes |
| https://github.com/discourse/discourse/releases/tag/v2026.5.1 | Release Notes |
| https://github.com/discourse/discourse/releases/tag/v2026.6.0 | Release Notes |
| https://github.com/discourse/discourse/security/advisories/GHSA-7wq5-jgww-5rw3 | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
14 Jul 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/discourse/discourse/security/advisories/GHSA-7wq5-jgww-5rw3 - Mitigation, Vendor Advisory |
13 Jul 2026, 14:33
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/discourse/discourse/commit/ca5a7e06167561928556afa2f237d67e459c6914 - Patch | |
| References | () https://github.com/discourse/discourse/releases/tag/v2026.1.5 - Release Notes | |
| References | () https://github.com/discourse/discourse/releases/tag/v2026.4.2 - Release Notes | |
| References | () https://github.com/discourse/discourse/releases/tag/v2026.5.1 - Release Notes | |
| References | () https://github.com/discourse/discourse/releases/tag/v2026.6.0 - Release Notes | |
| References | () https://github.com/discourse/discourse/security/advisories/GHSA-7wq5-jgww-5rw3 - Vendor Advisory, Mitigation | |
| CPE | cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:* cpe:2.3:a:discourse:discourse:2026.6.0:*:*:*:latest:*:*:* |
|
| First Time |
Discourse discourse
Discourse |
09 Jul 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-09 18:16
Updated : 2026-07-14 02:16
NVD link : CVE-2026-55420
Mitre link : CVE-2026-55420
CVE.ORG link : CVE-2026-55420
JSON object : View
Products Affected
discourse
- discourse
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
