CVE-2026-72721 | Discourse prior 2026.1.6/2026.5.2/2026.6.1/2026.7.0 Onebox DomainChecker.is_blocked redirect

SecurityVulns

A vulnerability described as problematic has been identified in Discourse. The affected element is the function Onebox::DomainChecker.is_blocked of the component Onebox. The manipulation results in open redirect.

This vulnerability is identified as CVE-2026-72721. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More