CyberRota Analysis
AI-GeneratedAuthenticated users of the Discourse open-source discussion platform prior to versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0 are vulnerable to eavesdropping on private AI bot conversations via the AI bot reply stream. This could lead to unauthorized access to sensitive information exchanged in these conversations. Organizations using affected versions should prioritize updating to the fixed releases to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated user could eavesdrop on private AI bot conversations through the AI bot reply stream. The issue is fixed in 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.