Private message title and participating users leaked in discourse
No sign of exploitation. No public exploitation artifact known so far.
A bug in Discourse exposed the titles and participant names of private messages containing groups to unauthorized users, though the actual message content remained protected. This leaked sensitive information about who was communicating privately and what they were discussing.
Information disclosure vulnerability in Discourse group private messaging where metadata (title and participant list) was inadvertently exposed in user inboxes despite intact access controls on message content. The issue affected versions where a specific commit exposed group PM metadata before being reverted within 32 minutes; users must upgrade to patched versions or the latest tests-passed branch.