CVE-2026-45788 | Discourse up to 2026.1.4/2026.4.1/2026.5.0 Secure Uploads pull_hotlinked_images unrestricted upload

SecurityVulns

A vulnerability classified as critical was found in Discourse up to 2026.1.4/2026.4.1/2026.5.0. This impacts the function pull_hotlinked_images of the component Secure Uploads. Such manipulation leads to unrestricted upload.

This vulnerability is uniquely identified as CVE-2026-45788. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More