CVE-2026-32113 MEDIUM

CVE-2026-32113: Discourse: Open redirect via `sso_destination_url` cookie in `enter`

Vendor Discourse
Product discourse
Weakness CWE-601 · Open redirect
Published March 31, 2026
Last update April 1, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N

What the vulnerability does

01Description

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the enter action in StaticController reads the sso_destination_url cookie and redirects to it with allow_other_host: true without validating the destination URL. While this cookie is normally set during legitimate DiscourseConnect Provider flows with cryptographically validated SSO payloads, cookies are client-controlled and can be set by attackers. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.

Key dates

02Disclosure timeline

March 31, 2026 CVE published
April 1, 2026 Record updated