CVE-2026-72729 | Discourse up to 2026.1.5/2026.5.1/2026.6.0 discourse-local-dates plugin cross-domain policy

SecurityVulns

A vulnerability was found in Discourse up to 2026.1.5/2026.5.1/2026.6.0. It has been declared as problematic. The affected element is an unknown function of the component discourse-local-dates plugin. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains.

This vulnerability appears as CVE-2026-72729. The attack may be performed from remote. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More