PatchSiren

Discord CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Discord CVE published 2026-01-22

CVE-2026-24332

CVE-2026-24332 is a medium-severity vulnerability in Discord that allows gathering information about whether a user's client state is Invisible. The vulnerability exists because the response to a WebSocket API request includes the user in the presences array with a status of 'offline', even though the user is not actually offline. This behavior is inconsistent with the UI description of Invisible as 'You [truncated]