MediaWiki Extensions and Skins Security Release Supplement (1.43.9/1.44.6/1.45.4)

Maryum Styles via Wikitech-l <[email protected]> Thu, 2 Jul 2026 13:43:45 -0700
Newsgroups gmane.science.linguistics.wikipedia.technical,gmane.org.wikimedia.mediawiki
Message-ID <CALBs+gGNEuUOCxMoTmMi4O+qxxkawp3z9_CY1wzR3fjHoaW6Mg@mail.gmail.com>
--===============8282899080873677677==
Content-Type: multipart/alternative; boundary="000000000000ec575c0655a6dde2"

--000000000000ec575c0655a6dde2
Content-Type: text/plain; charset="UTF-8"

Greetings-

With the security/maintenance release of MediaWiki 1.43.9/1.44.6/1.45.4, we
would also like to provide this supplementary announcement of MediaWiki
extensions and skins with now-public Phabricator tasks, security patches
and backports [1]:

UrlShortener
+ (T418533, CVE-2026-13706) - UrlShortener extension url validation can be
bypassed due to difference between php url parsing and WHATWG
https://gerrit.wikimedia.org/r/q/I64268dda19ea9dfa048b3e2212a682d53c2a59d6

RedirectManager
+ (T423826, CVE-2026-58518) - RedirectManager's API does not require a CSRF
token
https://gerrit.wikimedia.org/r/1275494

Cargo
+ (T424140, CVE-2026-58519) - Stored XSS through Cargo's map format
https://gerrit.wikimedia.org/r/c/1277612

UrlShortener
+ (T418431, CVE-2026-58520) - UrlShortener defaults to ineffective
validation open to third-party redirects
https://gerrit.wikimedia.org/r/1306769

CentralAuth
+ (T422306, CVE-2026-58028) - Pretty-printed API output combined with
centralauthtoken allows XSS with certain gadgets
https://gerrit.wikimedia.org/r/q/Idb42ab1cf685ef145b78701784909c590d758917

StructuredDiscussions
+ (T424285) - Flow ships Handlebars 3.0.0 with known security
vulnerabilities. See https://security.snyk.io/package/npm/handlebars/3.0.0
for more details
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Flow/+/1277782

Timeline
+ (T426631, CVE-2026-8857) - Full RCE using EasyTimeline Extension
https://gerrit.wikimedia.org/r/q/Ic2f3aa24922e6d44d063b76630cc888016ba4c74
https://gerrit.wikimedia.org/r/q/Ia19cbe8c80fa5a765abca68305254c15e817bfac

Timeline
+ (T427611, CVE-2026-58038) - Stored XSS through javascript URLs in SVGs
generated by EasyTimeline
https://gerrit.wikimedia.org/r/q/Ia61203fcd4913ce97fd6c05ea908d3910c213ff6

Maps
+ (GHSA-4h7g-5542-v3fc, CVE-2026-52854) - Stored XSS through the overlays
parameter in the display_map parser function
https://github.com/ProfessionalWiki/Maps/security/advisories/GHSA-4h7g-5542-v3fc
https://github.com/ProfessionalWiki/Maps/commit/737a993fc2f40499e9bb22198fd1d56c25613806

Cargo
+ (T428274, CVE-2026-58521) - SQLi in Cargo extension via year range filter
https://gerrit.wikimedia.org/r/1298854

OAuth
+(T428324, CVE-2026-13707) - Session fixation attacks on improperly
configured OAuth 1.0a tools
https://gerrit.wikimedia.org/r/q/Ife0b4bf16761c01bdb0e91a29f1fb94de380c73e

EmbedVideo (fork)
+(GHSA-c29q-5xm7-5p62, CVE-2026-55690) - Stored XSS via unsanitized service
name in exception text
https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-c29q-5xm7-5p62
https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/commit/9215564bf28a0ceb40be550a55ab78efc0accc56

EmbedVideo (fork)
+(GHSA-v65j-hff3-753c, CVE-2026-57440) - Stored XSS via malformed src url
with $wgEmbedVideoRequireConsent disabled
https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-v65j-hff3-753c
https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/commit/370156335b325bb81d14d89edf0a1f2643d50a84

EmbedVideo (fork)
+(GHSA-5c7p-g73q-rpg5, CVE-2026-55692) - Stored XSS via malformed src url
with $wgEmbedVideoRequireConsent enabled
https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-5c7p-g73q-rpg5
https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/commit/370156335b325bb81d14d89edf0a1f2643d50a84

EmbedVideo (fork)
+(GHSA-7h5p-637f-jfr7, CVE-2026-55691) - Stored XSS via unsanitized class
passed to template
https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-7h5p-637f-jfr7
https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/commit/370156335b325bb81d14d89edf0a1f2643d50a84

WikiLambda
+(T428833, CVE-2026-58517) - Blocked users can create and edit WikiLambda
objects
https://gerrit.wikimedia.org/r/1305376

Charts
+(T430548, CVE-2026-14358) - Stored XSS in Wikimedia Chart pie tooltip via
Data:*.tab field title
https://gerrit.wikimedia.org/r/q/Ibdaa7c852ae83f562e84dddc9c96ad64e2152210

Cargo
+(T422774, CVE-2026-14363) - Cargo Extension: SQLi in Special:Drilldown
https://gerrit.wikimedia.org/r/c/1269701
https://gerrit.wikimedia.org/r/c/1279498

The Wikimedia Security Team recommends updating these extensions and/or
skins to the current master branch or relevant, supported release branch
[2] as soon as possible. Some of the referenced Phabricator tasks above
_may_ still be private. Unfortunately, when security issues are reported,
sometimes sensitive information is exposed and since Phabricator is
historical, we cannot make these tasks public without exposing this
sensitive information. If you have any additional questions or concerns
regarding this update, please feel free to contact [email protected]
or file a security task within Phabricator [3]. CVE JSON references can be
found on Gitlab [4].

[1] https://phabricator.wikimedia.org/T421273
[2] https://www.mediawiki.org/wiki/Version_lifecycle
[3] https://www.mediawiki.org/wiki/Reporting_security_bugs
[4] https://gitlab.wikimedia.org/repos/security/wikimedia-cve-assignments

--000000000000ec575c0655a6dde2
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Greetings-<br><br>With the security/maintenance release of=
 MediaWiki 1.43.9/1.44.6/1.45.4, we would also like to provide this supplem=
entary announcement of MediaWiki extensions and skins with now-public Phabr=
icator tasks, security patches and backports [1]:<br><br>UrlShortener<br>+ =
(T418533, CVE-2026-13706) - UrlShortener extension url validation can be by=
passed due to difference between php url parsing and WHATWG<br><a href=3D"h=
ttps://gerrit.wikimedia.org/r/q/I64268dda19ea9dfa048b3e2212a682d53c2a59d6">=
https://gerrit.wikimedia.org/r/q/I64268dda19ea9dfa048b3e2212a682d53c2a59d6<=
/a><br><br>RedirectManager<br>+ (T423826, CVE-2026-58518) - RedirectManager=
&#39;s API does not require a CSRF token<br><a href=3D"https://gerrit.wikim=
edia.org/r/1275494">https://gerrit.wikimedia.org/r/1275494</a><br><br>Cargo=
<br>+ (T424140, CVE-2026-58519) - Stored XSS through Cargo&#39;s map format=
<br><a href=3D"https://gerrit.wikimedia.org/r/c/1277612">https://gerrit.wik=
imedia.org/r/c/1277612</a><br><br>UrlShortener<br>+ (T418431, CVE-2026-5852=
0) - UrlShortener defaults to ineffective validation open to third-party re=
directs<br><a href=3D"https://gerrit.wikimedia.org/r/1306769">https://gerri=
t.wikimedia.org/r/1306769</a><br><br>CentralAuth<br>+ (T422306, CVE-2026-58=
028) - Pretty-printed API output combined with centralauthtoken allows XSS =
with certain gadgets<br><a href=3D"https://gerrit.wikimedia.org/r/q/Idb42ab=
1cf685ef145b78701784909c590d758917">https://gerrit.wikimedia.org/r/q/Idb42a=
b1cf685ef145b78701784909c590d758917</a><br><br>StructuredDiscussions<br>+ (=
T424285) - Flow ships Handlebars 3.0.0 with known security vulnerabilities.=
 See <a href=3D"https://security.snyk.io/package/npm/handlebars/3.0.0">http=
s://security.snyk.io/package/npm/handlebars/3.0.0</a> for more details<br><=
a href=3D"https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Flow/+/1277=
782">https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Flow/+/1277782</=
a><br><br>Timeline<br>+ (T426631, CVE-2026-8857) - Full RCE using EasyTimel=
ine Extension<br><a href=3D"https://gerrit.wikimedia.org/r/q/Ic2f3aa24922e6=
d44d063b76630cc888016ba4c74">https://gerrit.wikimedia.org/r/q/Ic2f3aa24922e=
6d44d063b76630cc888016ba4c74</a><br><a href=3D"https://gerrit.wikimedia.org=
/r/q/Ia19cbe8c80fa5a765abca68305254c15e817bfac">https://gerrit.wikimedia.or=
g/r/q/Ia19cbe8c80fa5a765abca68305254c15e817bfac</a><br><br>Timeline<br>+ (T=
427611, CVE-2026-58038) - Stored XSS through javascript URLs in SVGs genera=
ted by EasyTimeline<br><a href=3D"https://gerrit.wikimedia.org/r/q/Ia61203f=
cd4913ce97fd6c05ea908d3910c213ff6">https://gerrit.wikimedia.org/r/q/Ia61203=
fcd4913ce97fd6c05ea908d3910c213ff6</a><br><br>Maps<br>+ (GHSA-4h7g-5542-v3f=
c, CVE-2026-52854) - Stored XSS through the overlays parameter in the displ=
ay_map parser function<br><a href=3D"https://github.com/ProfessionalWiki/Ma=
ps/security/advisories/GHSA-4h7g-5542-v3fc">https://github.com/Professional=
Wiki/Maps/security/advisories/GHSA-4h7g-5542-v3fc</a><br><a href=3D"https:/=
/github.com/ProfessionalWiki/Maps/commit/737a993fc2f40499e9bb22198fd1d56c25=
613806">https://github.com/ProfessionalWiki/Maps/commit/737a993fc2f40499e9b=
b22198fd1d56c25613806</a><br><br>Cargo<br>+ (T428274, CVE-2026-58521) - SQL=
i in Cargo extension via year range filter<br><a href=3D"https://gerrit.wik=
imedia.org/r/1298854">https://gerrit.wikimedia.org/r/1298854</a><br><br>OAu=
th<br>+(T428324, CVE-2026-13707) - Session fixation attacks on improperly c=
onfigured OAuth 1.0a tools<br><a href=3D"https://gerrit.wikimedia.org/r/q/I=
fe0b4bf16761c01bdb0e91a29f1fb94de380c73e">https://gerrit.wikimedia.org/r/q/=
Ife0b4bf16761c01bdb0e91a29f1fb94de380c73e</a><br><br>EmbedVideo (fork)<br>+=
(GHSA-c29q-5xm7-5p62, CVE-2026-55690) - Stored XSS via unsanitized service =
name in exception text<br><a href=3D"https://github.com/StarCitizenWiki/med=
iawiki-extensions-EmbedVideo/security/advisories/GHSA-c29q-5xm7-5p62">https=
://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advi=
sories/GHSA-c29q-5xm7-5p62</a><br><a href=3D"https://github.com/StarCitizen=
Wiki/mediawiki-extensions-EmbedVideo/commit/9215564bf28a0ceb40be550a55ab78e=
fc0accc56">https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVid=
eo/commit/9215564bf28a0ceb40be550a55ab78efc0accc56</a><br><br>EmbedVideo (f=
ork)<br>+(GHSA-v65j-hff3-753c, CVE-2026-57440) - Stored XSS via malformed s=
rc url with $wgEmbedVideoRequireConsent disabled<br><a href=3D"https://gith=
ub.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advisories/=
GHSA-v65j-hff3-753c">https://github.com/StarCitizenWiki/mediawiki-extension=
s-EmbedVideo/security/advisories/GHSA-v65j-hff3-753c</a><br><a href=3D"http=
s://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/commit/37015=
6335b325bb81d14d89edf0a1f2643d50a84">https://github.com/StarCitizenWiki/med=
iawiki-extensions-EmbedVideo/commit/370156335b325bb81d14d89edf0a1f2643d50a8=
4</a><br><br>EmbedVideo (fork)<br>+(GHSA-5c7p-g73q-rpg5, CVE-2026-55692) - =
Stored XSS via malformed src url with $wgEmbedVideoRequireConsent enabled<b=
r><a href=3D"https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedV=
ideo/security/advisories/GHSA-5c7p-g73q-rpg5">https://github.com/StarCitize=
nWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-5c7p-g73q-rp=
g5</a><br><a href=3D"https://github.com/StarCitizenWiki/mediawiki-extension=
s-EmbedVideo/commit/370156335b325bb81d14d89edf0a1f2643d50a84">https://githu=
b.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/commit/370156335b325b=
b81d14d89edf0a1f2643d50a84</a><br><br>EmbedVideo (fork)<br>+(GHSA-7h5p-637f=
-jfr7, CVE-2026-55691) - Stored XSS via unsanitized class passed to templat=
e<br><a href=3D"https://github.com/StarCitizenWiki/mediawiki-extensions-Emb=
edVideo/security/advisories/GHSA-7h5p-637f-jfr7">https://github.com/StarCit=
izenWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-7h5p-637f=
-jfr7</a><br><a href=3D"https://github.com/StarCitizenWiki/mediawiki-extens=
ions-EmbedVideo/commit/370156335b325bb81d14d89edf0a1f2643d50a84">https://gi=
thub.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/commit/370156335b3=
25bb81d14d89edf0a1f2643d50a84</a><br><br>WikiLambda<br>+(T428833, CVE-2026-=
58517) - Blocked users can create and edit WikiLambda objects<br><a href=3D=
"https://gerrit.wikimedia.org/r/1305376">https://gerrit.wikimedia.org/r/130=
5376</a><br><br>Charts<br>+(T430548, CVE-2026-14358) - Stored XSS in Wikime=
dia Chart pie tooltip via Data:*.tab field title<br><a href=3D"https://gerr=
it.wikimedia.org/r/q/Ibdaa7c852ae83f562e84dddc9c96ad64e2152210">https://ger=
rit.wikimedia.org/r/q/Ibdaa7c852ae83f562e84dddc9c96ad64e2152210</a><br><br>=
Cargo<br>+(T422774, CVE-2026-14363) - Cargo Extension: SQLi in Special:Dril=
ldown<br><a href=3D"https://gerrit.wikimedia.org/r/c/1269701">https://gerri=
t.wikimedia.org/r/c/1269701</a><br><a href=3D"https://gerrit.wikimedia.org/=
r/c/1279498">https://gerrit.wikimedia.org/r/c/1279498</a><br><br>The Wikime=
dia Security Team recommends updating these extensions and/or skins to the =
current master branch or relevant, supported release branch [2] as soon as =
possible. Some of the referenced Phabricator tasks above _may_ still be pri=
vate. Unfortunately, when security issues are reported, sometimes sensitive=
 information is exposed and since Phabricator is historical, we cannot make=
 these tasks public without exposing this sensitive information. If you hav=
e any additional questions or concerns regarding this update, please feel f=
ree to contact <a href=3D"mailto:[email protected]">security@wikimedia=
.org</a> or file a security task within Phabricator [3]. CVE JSON reference=
s can be found on Gitlab [4].<br><br>[1] <a href=3D"https://phabricator.wik=
imedia.org/T421273">https://phabricator.wikimedia.org/T421273</a><br>[2] <a=
 href=3D"https://www.mediawiki.org/wiki/Version_lifecycle">https://www.medi=
awiki.org/wiki/Version_lifecycle</a><br>[3] <a href=3D"https://www.mediawik=
i.org/wiki/Reporting_security_bugs">https://www.mediawiki.org/wiki/Reportin=
g_security_bugs</a><br>[4] <a href=3D"https://gitlab.wikimedia.org/repos/se=
curity/wikimedia-cve-assignments">https://gitlab.wikimedia.org/repos/securi=
ty/wikimedia-cve-assignments</a></div>

--000000000000ec575c0655a6dde2--

--===============8282899080873677677==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Wikitech-l mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://lists.wikimedia.org/postorius/lists/wikitech-l.lists.wikimedia.org/
--===============8282899080873677677==--