Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-0677

NIXPKGS-2026-0677
published on
updated 2 months ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt ignored
    6 packages
    • discourseAllPlugins
    • discourse-mail-receiver
    • python312Packages.pydiscourse
    • python313Packages.pydiscourse
    • python314Packages.pydiscourse
    • grafanaPlugins.grafana-discourse-datasource
  • @mweinelt published on GitHub
Discourse hasUnauthorized Exposure of Private User Action Types

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a user could access another user's private activity due to insufficient authorization checks in the user actions endpoint. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch.

Affected products

discourse
  • ==>= 2026.1.0-latest, < 2026.1.2
  • === 2026.3.0-latest.1
  • ==>= 2026.2.0-latest, < 2026.2.1

Matching in nixpkgs

Ignored packages (6)

Package maintainers

https://github.com/discourse/discourse/security/advisories/GHSA-ww5f-24g5-c33g