CVE-2026-72724 | Discourse up to 2026.1.5/2026.5.1/2026.6.0 Onebox onebox_handler.rb thread_id information disclosure
A vulnerability, which was classified as problematic, has been found in Discourse up to 2026.1.5/2026.5.1/2026.6.0. This impacts an unknown function of the file plugins/chat/lib/chat/onebox_handler.rb of the component Onebox. Performing a manipulation of the argument thread_id results in information disclosure.
This vulnerability is cataloged as CVE-2026-72724. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More