Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-default configurations, processing of PDF uploads could be exploited to obtain RCE on the server. This issue is patched in 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
References
| Link | Resource |
|---|---|
| https://github.com/discourse/discourse/commit/ca5a7e06167561928556afa2f237d67e459c6914 | Patch |
| https://github.com/discourse/discourse/releases/tag/v2026.1.5 | Release Notes |
| https://github.com/discourse/discourse/releases/tag/v2026.4.2 | Release Notes |
| https://github.com/discourse/discourse/releases/tag/v2026.5.1 | Release Notes |
| https://github.com/discourse/discourse/releases/tag/v2026.6.0 | Release Notes |
| https://github.com/discourse/discourse/security/advisories/GHSA-7wq5-jgww-5rw3 | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-07-09 18:16
Updated : 2026-07-14 02:16
NVD link : CVE-2026-55420
Mitre link : CVE-2026-55420
CVE.ORG link : CVE-2026-55420
JSON object : View
Products Affected
discourse
- discourse
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
