This repository was archived by the owner on Jul 22, 2025. It is now read-only.
XSS via Discourse-ai SharedAiConversation onebox
Package
Discourse AI
(Discourse)
Affected versions
< 7ebbcd2
Patched versions
None
Impact
When sharing Discourse AI Bot conversations into posts, if the conversation had HTML entities those could leak into the Discourse application when a user visited a post with a onebox to said conversation.
Patches
This issue is patched in the latest version of Discourse AI
Workarounds
Remove all groups from
ai bot public sharing allowed groups
site setting.