Discourse <=2026.7.0 QAPage JSON-LD leaks hidden firstpost
CVE-2026-53960 Published on August 17, 2026
Discourse: Hidden first-post excerpt is emitted in Q&A schema JSON-LD
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post content was leaked as an excerpt in the publicly-served Q&A (QAPage) JSON-LD structured data, exposing it to any unauthenticated visitor and to search-engine crawlers. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
Vulnerability Analysis
CVE-2026-53960 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-53960 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-53960
Want to know whenever a new CVE is published for Discourse? stack.watch will email you.
Affected Versions
discourse:- Version < 2026.1.6 is affected.
- Version >= 2026.5.0-latest, < 2026.5.2 is affected.
- Version >= 2026.6.0-latest, < 2026.6.1 is affected.