Pull 4961 question

The following PR and Commit was flagged as SECURITY:
https://github.com/discourse/discourse/pull/4961
https://github.com/discourse/discourse/pull/4961/commits/7023260786524fe7fde2043268a6283bdf461c1a

Can anyone explain the scenario / risk for this?

Thanks!

This has to do with a potential vulnerability that may affect users of the software and as such we do not feel comfortable disclosing the details at this time.

7 Likes