MediaWiki Extensions and Skins Security Release Supplement (1.43.9/1.44.6/1.45.4)
Maryum Styles via Wikitech-l <[email protected]> Thu, 2 Jul 2026 13:43:45 -0700
| Newsgroups | gmane.science.linguistics.wikipedia.technical,gmane.org.wikimedia.mediawiki |
|---|---|
| Message-ID | <CALBs+gGNEuUOCxMoTmMi4O+qxxkawp3z9_CY1wzR3fjHoaW6Mg@mail.gmail.com> |
--===============8282899080873677677== Content-Type: multipart/alternative; boundary="000000000000ec575c0655a6dde2" --000000000000ec575c0655a6dde2 Content-Type: text/plain; charset="UTF-8" Greetings- With the security/maintenance release of MediaWiki 1.43.9/1.44.6/1.45.4, we would also like to provide this supplementary announcement of MediaWiki extensions and skins with now-public Phabricator tasks, security patches and backports [1]: UrlShortener + (T418533, CVE-2026-13706) - UrlShortener extension url validation can be bypassed due to difference between php url parsing and WHATWG https://gerrit.wikimedia.org/r/q/I64268dda19ea9dfa048b3e2212a682d53c2a59d6 RedirectManager + (T423826, CVE-2026-58518) - RedirectManager's API does not require a CSRF token https://gerrit.wikimedia.org/r/1275494 Cargo + (T424140, CVE-2026-58519) - Stored XSS through Cargo's map format https://gerrit.wikimedia.org/r/c/1277612 UrlShortener + (T418431, CVE-2026-58520) - UrlShortener defaults to ineffective validation open to third-party redirects https://gerrit.wikimedia.org/r/1306769 CentralAuth + (T422306, CVE-2026-58028) - Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets https://gerrit.wikimedia.org/r/q/Idb42ab1cf685ef145b78701784909c590d758917 StructuredDiscussions + (T424285) - Flow ships Handlebars 3.0.0 with known security vulnerabilities. See https://security.snyk.io/package/npm/handlebars/3.0.0 for more details https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Flow/+/1277782 Timeline + (T426631, CVE-2026-8857) - Full RCE using EasyTimeline Extension https://gerrit.wikimedia.org/r/q/Ic2f3aa24922e6d44d063b76630cc888016ba4c74 https://gerrit.wikimedia.org/r/q/Ia19cbe8c80fa5a765abca68305254c15e817bfac Timeline + (T427611, CVE-2026-58038) - Stored XSS through javascript URLs in SVGs generated by EasyTimeline https://gerrit.wikimedia.org/r/q/Ia61203fcd4913ce97fd6c05ea908d3910c213ff6 Maps + (GHSA-4h7g-5542-v3fc, CVE-2026-52854) - Stored XSS through the overlays parameter in the display_map parser function https://github.com/ProfessionalWiki/Maps/security/advisories/GHSA-4h7g-5542-v3fc https://github.com/ProfessionalWiki/Maps/commit/737a993fc2f40499e9bb22198fd1d56c25613806 Cargo + (T428274, CVE-2026-58521) - SQLi in Cargo extension via year range filter https://gerrit.wikimedia.org/r/1298854 OAuth +(T428324, CVE-2026-13707) - Session fixation attacks on improperly configured OAuth 1.0a tools https://gerrit.wikimedia.org/r/q/Ife0b4bf16761c01bdb0e91a29f1fb94de380c73e EmbedVideo (fork) +(GHSA-c29q-5xm7-5p62, CVE-2026-55690) - Stored XSS via unsanitized service name in exception text https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-c29q-5xm7-5p62 https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/commit/9215564bf28a0ceb40be550a55ab78efc0accc56 EmbedVideo (fork) +(GHSA-v65j-hff3-753c, CVE-2026-57440) - Stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-v65j-hff3-753c https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/commit/370156335b325bb81d14d89edf0a1f2643d50a84 EmbedVideo (fork) +(GHSA-5c7p-g73q-rpg5, CVE-2026-55692) - Stored XSS via malformed src url with $wgEmbedVideoRequireConsent enabled https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-5c7p-g73q-rpg5 https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/commit/370156335b325bb81d14d89edf0a1f2643d50a84 EmbedVideo (fork) +(GHSA-7h5p-637f-jfr7, CVE-2026-55691) - Stored XSS via unsanitized class passed to template https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-7h5p-637f-jfr7 https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/commit/370156335b325bb81d14d89edf0a1f2643d50a84 WikiLambda +(T428833, CVE-2026-58517) - Blocked users can create and edit WikiLambda objects https://gerrit.wikimedia.org/r/1305376 Charts +(T430548, CVE-2026-14358) - Stored XSS in Wikimedia Chart pie tooltip via Data:*.tab field title https://gerrit.wikimedia.org/r/q/Ibdaa7c852ae83f562e84dddc9c96ad64e2152210 Cargo +(T422774, CVE-2026-14363) - Cargo Extension: SQLi in Special:Drilldown https://gerrit.wikimedia.org/r/c/1269701 https://gerrit.wikimedia.org/r/c/1279498 The Wikimedia Security Team recommends updating these extensions and/or skins to the current master branch or relevant, supported release branch [2] as soon as possible. Some of the referenced Phabricator tasks above _may_ still be private. Unfortunately, when security issues are reported, sometimes sensitive information is exposed and since Phabricator is historical, we cannot make these tasks public without exposing this sensitive information. If you have any additional questions or concerns regarding this update, please feel free to contact [email protected] or file a security task within Phabricator [3]. CVE JSON references can be found on Gitlab [4]. [1] https://phabricator.wikimedia.org/T421273 [2] https://www.mediawiki.org/wiki/Version_lifecycle [3] https://www.mediawiki.org/wiki/Reporting_security_bugs [4] https://gitlab.wikimedia.org/repos/security/wikimedia-cve-assignments --000000000000ec575c0655a6dde2 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Greetings-<br><br>With the security/maintenance release of= MediaWiki 1.43.9/1.44.6/1.45.4, we would also like to provide this supplem= entary announcement of MediaWiki extensions and skins with now-public Phabr= icator tasks, security patches and backports [1]:<br><br>UrlShortener<br>+ = (T418533, CVE-2026-13706) - UrlShortener extension url validation can be by= passed due to difference between php url parsing and WHATWG<br><a href=3D"h= ttps://gerrit.wikimedia.org/r/q/I64268dda19ea9dfa048b3e2212a682d53c2a59d6">= https://gerrit.wikimedia.org/r/q/I64268dda19ea9dfa048b3e2212a682d53c2a59d6<= /a><br><br>RedirectManager<br>+ (T423826, CVE-2026-58518) - RedirectManager= 's API does not require a CSRF token<br><a href=3D"https://gerrit.wikim= edia.org/r/1275494">https://gerrit.wikimedia.org/r/1275494</a><br><br>Cargo= <br>+ (T424140, CVE-2026-58519) - Stored XSS through Cargo's map format= <br><a href=3D"https://gerrit.wikimedia.org/r/c/1277612">https://gerrit.wik= imedia.org/r/c/1277612</a><br><br>UrlShortener<br>+ (T418431, CVE-2026-5852= 0) - UrlShortener defaults to ineffective validation open to third-party re= directs<br><a href=3D"https://gerrit.wikimedia.org/r/1306769">https://gerri= t.wikimedia.org/r/1306769</a><br><br>CentralAuth<br>+ (T422306, CVE-2026-58= 028) - Pretty-printed API output combined with centralauthtoken allows XSS = with certain gadgets<br><a href=3D"https://gerrit.wikimedia.org/r/q/Idb42ab= 1cf685ef145b78701784909c590d758917">https://gerrit.wikimedia.org/r/q/Idb42a= b1cf685ef145b78701784909c590d758917</a><br><br>StructuredDiscussions<br>+ (= T424285) - Flow ships Handlebars 3.0.0 with known security vulnerabilities.= See <a href=3D"https://security.snyk.io/package/npm/handlebars/3.0.0">http= s://security.snyk.io/package/npm/handlebars/3.0.0</a> for more details<br><= a href=3D"https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Flow/+/1277= 782">https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Flow/+/1277782</= a><br><br>Timeline<br>+ (T426631, CVE-2026-8857) - Full RCE using EasyTimel= ine Extension<br><a href=3D"https://gerrit.wikimedia.org/r/q/Ic2f3aa24922e6= d44d063b76630cc888016ba4c74">https://gerrit.wikimedia.org/r/q/Ic2f3aa24922e= 6d44d063b76630cc888016ba4c74</a><br><a href=3D"https://gerrit.wikimedia.org= /r/q/Ia19cbe8c80fa5a765abca68305254c15e817bfac">https://gerrit.wikimedia.or= g/r/q/Ia19cbe8c80fa5a765abca68305254c15e817bfac</a><br><br>Timeline<br>+ (T= 427611, CVE-2026-58038) - Stored XSS through javascript URLs in SVGs genera= ted by EasyTimeline<br><a href=3D"https://gerrit.wikimedia.org/r/q/Ia61203f= cd4913ce97fd6c05ea908d3910c213ff6">https://gerrit.wikimedia.org/r/q/Ia61203= fcd4913ce97fd6c05ea908d3910c213ff6</a><br><br>Maps<br>+ (GHSA-4h7g-5542-v3f= c, CVE-2026-52854) - Stored XSS through the overlays parameter in the displ= ay_map parser function<br><a href=3D"https://github.com/ProfessionalWiki/Ma= ps/security/advisories/GHSA-4h7g-5542-v3fc">https://github.com/Professional= Wiki/Maps/security/advisories/GHSA-4h7g-5542-v3fc</a><br><a href=3D"https:/= /github.com/ProfessionalWiki/Maps/commit/737a993fc2f40499e9bb22198fd1d56c25= 613806">https://github.com/ProfessionalWiki/Maps/commit/737a993fc2f40499e9b= b22198fd1d56c25613806</a><br><br>Cargo<br>+ (T428274, CVE-2026-58521) - SQL= i in Cargo extension via year range filter<br><a href=3D"https://gerrit.wik= imedia.org/r/1298854">https://gerrit.wikimedia.org/r/1298854</a><br><br>OAu= th<br>+(T428324, CVE-2026-13707) - Session fixation attacks on improperly c= onfigured OAuth 1.0a tools<br><a href=3D"https://gerrit.wikimedia.org/r/q/I= fe0b4bf16761c01bdb0e91a29f1fb94de380c73e">https://gerrit.wikimedia.org/r/q/= Ife0b4bf16761c01bdb0e91a29f1fb94de380c73e</a><br><br>EmbedVideo (fork)<br>+= (GHSA-c29q-5xm7-5p62, CVE-2026-55690) - Stored XSS via unsanitized service = name in exception text<br><a href=3D"https://github.com/StarCitizenWiki/med= iawiki-extensions-EmbedVideo/security/advisories/GHSA-c29q-5xm7-5p62">https= ://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advi= sories/GHSA-c29q-5xm7-5p62</a><br><a href=3D"https://github.com/StarCitizen= Wiki/mediawiki-extensions-EmbedVideo/commit/9215564bf28a0ceb40be550a55ab78e= fc0accc56">https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVid= eo/commit/9215564bf28a0ceb40be550a55ab78efc0accc56</a><br><br>EmbedVideo (f= ork)<br>+(GHSA-v65j-hff3-753c, CVE-2026-57440) - Stored XSS via malformed s= rc url with $wgEmbedVideoRequireConsent disabled<br><a href=3D"https://gith= ub.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advisories/= GHSA-v65j-hff3-753c">https://github.com/StarCitizenWiki/mediawiki-extension= s-EmbedVideo/security/advisories/GHSA-v65j-hff3-753c</a><br><a href=3D"http= s://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/commit/37015= 6335b325bb81d14d89edf0a1f2643d50a84">https://github.com/StarCitizenWiki/med= iawiki-extensions-EmbedVideo/commit/370156335b325bb81d14d89edf0a1f2643d50a8= 4</a><br><br>EmbedVideo (fork)<br>+(GHSA-5c7p-g73q-rpg5, CVE-2026-55692) - = Stored XSS via malformed src url with $wgEmbedVideoRequireConsent enabled<b= r><a href=3D"https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedV= ideo/security/advisories/GHSA-5c7p-g73q-rpg5">https://github.com/StarCitize= nWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-5c7p-g73q-rp= g5</a><br><a href=3D"https://github.com/StarCitizenWiki/mediawiki-extension= s-EmbedVideo/commit/370156335b325bb81d14d89edf0a1f2643d50a84">https://githu= b.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/commit/370156335b325b= b81d14d89edf0a1f2643d50a84</a><br><br>EmbedVideo (fork)<br>+(GHSA-7h5p-637f= -jfr7, CVE-2026-55691) - Stored XSS via unsanitized class passed to templat= e<br><a href=3D"https://github.com/StarCitizenWiki/mediawiki-extensions-Emb= edVideo/security/advisories/GHSA-7h5p-637f-jfr7">https://github.com/StarCit= izenWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-7h5p-637f= -jfr7</a><br><a href=3D"https://github.com/StarCitizenWiki/mediawiki-extens= ions-EmbedVideo/commit/370156335b325bb81d14d89edf0a1f2643d50a84">https://gi= thub.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/commit/370156335b3= 25bb81d14d89edf0a1f2643d50a84</a><br><br>WikiLambda<br>+(T428833, CVE-2026-= 58517) - Blocked users can create and edit WikiLambda objects<br><a href=3D= "https://gerrit.wikimedia.org/r/1305376">https://gerrit.wikimedia.org/r/130= 5376</a><br><br>Charts<br>+(T430548, CVE-2026-14358) - Stored XSS in Wikime= dia Chart pie tooltip via Data:*.tab field title<br><a href=3D"https://gerr= it.wikimedia.org/r/q/Ibdaa7c852ae83f562e84dddc9c96ad64e2152210">https://ger= rit.wikimedia.org/r/q/Ibdaa7c852ae83f562e84dddc9c96ad64e2152210</a><br><br>= Cargo<br>+(T422774, CVE-2026-14363) - Cargo Extension: SQLi in Special:Dril= ldown<br><a href=3D"https://gerrit.wikimedia.org/r/c/1269701">https://gerri= t.wikimedia.org/r/c/1269701</a><br><a href=3D"https://gerrit.wikimedia.org/= r/c/1279498">https://gerrit.wikimedia.org/r/c/1279498</a><br><br>The Wikime= dia Security Team recommends updating these extensions and/or skins to the = current master branch or relevant, supported release branch [2] as soon as = possible. Some of the referenced Phabricator tasks above _may_ still be pri= vate. Unfortunately, when security issues are reported, sometimes sensitive= information is exposed and since Phabricator is historical, we cannot make= these tasks public without exposing this sensitive information. If you hav= e any additional questions or concerns regarding this update, please feel f= ree to contact <a href=3D"mailto:[email protected]">security@wikimedia= .org</a> or file a security task within Phabricator [3]. CVE JSON reference= s can be found on Gitlab [4].<br><br>[1] <a href=3D"https://phabricator.wik= imedia.org/T421273">https://phabricator.wikimedia.org/T421273</a><br>[2] <a= href=3D"https://www.mediawiki.org/wiki/Version_lifecycle">https://www.medi= awiki.org/wiki/Version_lifecycle</a><br>[3] <a href=3D"https://www.mediawik= i.org/wiki/Reporting_security_bugs">https://www.mediawiki.org/wiki/Reportin= g_security_bugs</a><br>[4] <a href=3D"https://gitlab.wikimedia.org/repos/se= curity/wikimedia-cve-assignments">https://gitlab.wikimedia.org/repos/securi= ty/wikimedia-cve-assignments</a></div> --000000000000ec575c0655a6dde2-- --===============8282899080873677677== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Wikitech-l mailing list -- [email protected] To unsubscribe send an email to [email protected] https://lists.wikimedia.org/postorius/lists/wikitech-l.lists.wikimedia.org/ --===============8282899080873677677==--