v2026.1.0-latest → v2026.1.0
Highlights
High context topic cards
Our Horizon theme now supports a new, experimental option to show high context topic cards, with additional information for tags, assignments, solutions, and topic votes.
Use "Hot" as default topic list for categories
Admins can now configure "Hot" to be the default topic list for individual categories.
New site for releases and changelogs
A new releases.discourse.org site is now available where you can see changelogs for Discourse, including upcoming and past releases.
Carousel display for images in posts
When you include multiple images in a post, you can now choose between displaying them in a grid or in a new carousel mode. Switching is as simple as selecting the option in the top-right corner of the gallery in the rich text editor.
Access common chat channel actions from the sidebar context menu
We’ve made it easier to access common actions for chat channels on desktop with a sidebar context menu. This works for both public and direct message channels. From here, you will be able to do the following actions: * Change the notification level for the channel, including muting or unmuting * Go directly to the channel settings * Star or unstar the channel * Leave the channel
Security Fixes
AI Discover's continue conversation allows to impersonate user
DoS vulnerability in username change endpoint
Users archives leaked to users with moderation privileges
Moderators can access admin-only reports exposing private upload URLs
Insecure default configuration allows non-admin moderators to non-staff accounts via email change
Staff action logs expose sensitive information to moderators
Subscriptions are susceptible to takeover
FinalDestination hostname matching allows SSRF protection bypass
Permalinks to restricted resources leak resource slugs to unauthorized users
Topic conversion permission vulnerability for moderators
Non-admin moderators can exfiltrate private content via post ownership transfer
Denial of Service (DoS) Vulnerability in Drafts Creation Endpoint
Script execution in uploaded HTML/XML files on S3
Stored XSS via Katex in discourse-math plugin