The following PR and Commit was flagged as SECURITY:
https://github.com/discourse/discourse/pull/4961
https://github.com/discourse/discourse/pull/4961/commits/7023260786524fe7fde2043268a6283bdf461c1a
Can anyone explain the scenario / risk for this?
Thanks!