# Vulnerability in Discourse software

**URL:** <https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796>\
**Category:** Site Feedback\
**Created:** [May 30, 2023, 11:51pm UTC](https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796 "2023-05-30T23:51:58Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Pleonast](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pleonast/32/1183_2.png) [@Pleonast](https://boards.straightdope.com/u/Pleonast)\
**Post date:** [May 30, 2023, 8:15pm UTC](https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796/2 "2023-05-30T20:15:23Z")

</div>

> [@Test thread — to test things out. Do not lock!](https://boards.straightdope.com/t/test-thread-to-test-things-out-do-not-lock/956736/395):
>
> Discourse faithfully sent them to your browser

Shouldn’t that be a bug? Passing unknown tags seems exploitable.

[← previous page](https://boards.straightdope.com/t/the-trial-of-elizabeth-holmes-theranos-sentenced-to-11-yrs-18nov2022/946138?page=33)

---

_[View the full topic](https://boards.straightdope.com/t/vulnerability-in-discourse-software/984796)._
