CVE-2026-27162
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `posts_nearby` was
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, posts_nearby was checking topic access but then returning all posts regardless of type, including whispers that should only be visible to whisperers. Use Post.secured(guardian) to properly filter post types based on user permissions.
Versions 2025.12.2, 2026.1.1, and 2026.2.0 patch the issue. No known workarounds are available.
MEDIUM · CVSS 4.9
EPSS 0.00047
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0