# Vulnerability in Discourse software

**URL:** <https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796>\
**Category:** Site Feedback\
**Created:** [May 30, 2023, 11:51pm UTC](https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796 "2023-05-30T23:51:58Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![engineer\_comp\_geek](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/engineer_comp_geek/32/504_2.png) [@engineer\_comp\_geek](https://boards.straightdope.com/u/engineer_comp_geek)\
**Post date:** [May 30, 2023, 11:51pm UTC](https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796/1 "2023-05-30T23:51:58Z")

</div>

This is to create a new thread for an issue that was found in the Test Thread in ATMB.

This was in response to the following post:

> [@Test thread — to test things out. Do not lock!](https://boards.straightdope.com/t/test-thread-to-test-things-out-do-not-lock/956736/395):
>
> That’s entirely down to \< and \> being the delimiters for HTML commands.
> 
> Some of which Discourse respects and passes along to the browser verbatim, like superscript and subscript, whereas others are suppressed like. And others are simply passed through to the browser which ignores them as nonsense, leaving nothing visible in that spot. The word “stuff” here is inside tags which are meaningless in html and so although Discourse faithfully sent them to your browser, it ignored them as nonsense and displays nothing.

---

<div class="post-metadata">

**Author:** ![Pleonast](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pleonast/32/1183_2.png) [@Pleonast](https://boards.straightdope.com/u/Pleonast)\
**Post date:** [May 30, 2023, 8:15pm UTC](https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796/2 "2023-05-30T20:15:23Z")

</div>

> [@Test thread — to test things out. Do not lock!](https://boards.straightdope.com/t/test-thread-to-test-things-out-do-not-lock/956736/395):
>
> Discourse faithfully sent them to your browser

Shouldn’t that be a bug? Passing unknown tags seems exploitable.

[← previous page](https://boards.straightdope.com/t/the-trial-of-elizabeth-holmes-theranos-sentenced-to-11-yrs-18nov2022/946138?page=33)

---

<div class="post-metadata">

**Author:** ![Pleonast](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pleonast/32/1183_2.png) [@Pleonast](https://boards.straightdope.com/u/Pleonast)\
**Post date:** [May 30, 2023, 8:17pm UTC](https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796/3 "2023-05-30T20:17:29Z")

</div>

Yep, definitely exploitable. I managed to put in a page navigation item into my post. That is benign and I won’t try anything else. This needs to be fixed.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [May 30, 2023, 8:20pm UTC](https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796/4 "2023-05-30T20:20:01Z")

</div>

There are some things Discourse filters. I know I don’t know what they are. \<script\> tags for sure. \<iframe\> too it seems.

---

<div class="post-metadata">

**Author:** ![Pleonast](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pleonast/32/1183_2.png) [@Pleonast](https://boards.straightdope.com/u/Pleonast)\
**Post date:** [May 31, 2023, 12:29am UTC](https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796/5 "2023-05-31T00:29:30Z")

</div>

Thanks for the new thread.

I’m not up-to-date enough on web coding to know what’s actually dangerous anymore. And anyway, it needs to be reviewed on the code side.

I just get a bad feeling when the filter seems to be a blocklist rather than a passlist.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [May 31, 2023, 2:17am UTC](https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796/6 "2023-05-31T02:17:41Z")

</div>

> [@Pleonast](#):
>
> I just get a bad feeling when the filter seems to be a blocklist rather than a passlist.

Agree that’s called “open-endedly dangerous”.

FYI, **ecg** ’s quote of my post in the other thread that forms most of the OP here in this thread has had a bunch of my formatting content and properly escaped display-only html stripped out. It doesn’t alter the fundamental point of my post but it does make it seem like I was having a major brain attack while writing it.

---

<div class="post-metadata">

**Author:** ![Max\_S](https://avatars.discourse-cdn.com/v4/letter/m/46a35a/32.png) [@Max\_S](https://boards.straightdope.com/u/Max_S)\
**Post date:** [May 31, 2023, 3:04am UTC](https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796/7 "2023-05-31T03:04:26Z")

</div>

I’m pretty sure this isn’t a bug, let alone a vulnerability. Discourse posts are written in a Markdown variant (extensions include limited BBCode support, link previews, etc.). Markdown itself [allows](https://spec.commonmark.org/0.30/#raw-html) the usage of inline HTML. Discourse’s [Markdown sanitizer](https://github.com/discourse/discourse/blob/main/lib/pretty_text.rb) already uses a whitelist and purposely replaces unrecognized tags with whitespace.

ETA: For example, `style` attributes are sanitized but you can still post `div` elements aligned using the legacy HTML `align` attribute, which is on [the whitelist](https://github.com/discourse/discourse/blob/33087f0bdf17aea7942cbb02672c9cd83f7545ee/app/assets/javascripts/pretty-text/addon/allow-lister.js):

```auto
<div align="center">Centered Text</div>

```

Centered Text

~Max

---

<div class="post-metadata">

**Author:** ![scudsucker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scudsucker/32/14101_2.png) [@scudsucker](https://boards.straightdope.com/u/scudsucker)\
**Post date:** [May 31, 2023, 9:07am UTC](https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796/8 "2023-05-31T09:07:42Z")

</div>

All I want is the `<marquee>` tag to work…

---

<div class="post-metadata">

**Author:** ![What\_Exit](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/what_exit/32/10652_2.png) [@What\_Exit](https://boards.straightdope.com/u/What_Exit)\
**Post date:** [May 31, 2023, 1:11pm UTC](https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796/9 "2023-05-31T13:11:37Z")

</div>

I’m sorry but the marquee has been Deprecated and Mocked relentlessly.

---

<div class="post-metadata">

**Author:** ![Atamasama](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/atamasama/32/12961_2.png) [@Atamasama](https://boards.straightdope.com/u/Atamasama)\
**Post date:** [May 31, 2023, 2:13pm UTC](https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796/10 "2023-05-31T14:13:52Z")

</div>

I miss it. ☹

[![](https://res.cloudinary.com/practicaldev/image/fetch/s--4D_2ZM6z--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_66%2Cw_880/https://dev-to-uploads.s3.amazonaws.com/i/vbhtv2nzy5te2pc3lyxv.gif) ](https://res.cloudinary.com/practicaldev/image/fetch/s--4D_2ZM6z--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_66%2Cw_880/https://dev-to-uploads.s3.amazonaws.com/i/vbhtv2nzy5te2pc3lyxv.gif)

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [May 31, 2023, 4:53pm UTC](https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796/11 "2023-05-31T16:53:42Z")

</div>

\<marquee\> and \<blink\> are the two I want back. 🙂
