CVE-2026-72721 | Discourse prior 2026.1.6/2026.5.2/2026.6.1/2026.7.0 Onebox DomainChecker.is_blocked redirect
A vulnerability described as problematic has been identified in Discourse. The affected element is the function Onebox::DomainChecker.is_blocked of the component Onebox. The manipulation results in open redirect.
This vulnerability is identified as CVE-2026-72721. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More