Greetings- With the security/maintenance release of MediaWiki 1.43.10/1.45.5/1.46.1, we would also like to provide this supplementary announcement of MediaWiki extensions and skins with now-public Phabricator tasks, security patches and backports [1]:
WikiLambda + (T428829, CVE-2026-103046) - WikifunctionsFragmentRenderer does unsafe string replacements on user-provided HTML https://gerrit.wikimedia.org/r/c/1307827 EasyTimeline + (T428006, CVE-2026-103044) - EasyTimeline should not serve image maps as application/xml https://gerrit.wikimedia.org/r/c/1346078 Refreshed + (T268377, CVE-2026-103045) - XSS in RefreshedTemplate https://gerrit.wikimedia.org/r/c/1309277 CentralAuth + (T244682, CVE-2026-103047) - i18n message that is not in $wgRawHtmlMessages unsafely used in CentralAuth in uncommon configuration https://gerrit.wikimedia.org/r/c/1309285 Collection + (T321092, CVE-2026-103048) - Open Redirect in Special:Book https://gerrit.wikimedia.org/r/c/1346083 Cargo + (T431567, CVE-2026-103049) - XSS in Cargo's Special:CargoQuery page due to unsanitized table headers https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1310132 MassMessage + (T432341, CVE-2026-103050) - Stored i18n XSS in MassMessage https://gerrit.wikimedia.org/r/c/1346089 CentralNotice + (T432419, CVE-2026-103051) - Stored i18n XSSs in CentralNotice https://gerrit.wikimedia.org/r/c/1346103 Thanks + (T432424, CVE-2026-100237) - Stored i18n XSS in the Flow integration of Thanks https://gerrit.wikimedia.org/r/c/1345173 StructuredDiscussions + (T432425, CVE-2026-100238) - Stored i18n XSSs in Flow https://gerrit.wikimedia.org/r/q/Ic6149363fe1de2440240fe88aebfd4ae30cea606 TemplateSandbox + (T407974, CVE-2026-100240) - Extension:TemplateSandbox does not check for authorizeRead for the page being previewed https://gerrit.wikimedia.org/r/q/Iaf9f6e2280798af5516197257ddc0264b9ad9fb7 EventBus + (T432948, CVE-2026-100241) - Private change tags exposed to anonymous users via public EventStreams https://gerrit.wikimedia.org/r/c/1346065 DataTransfer + (T433275, CVE-2026-100242) - Extension:DataTransfer affected by CVE-2026-59933 https://gerrit.wikimedia.org/r/1318179 WikiSEO + (T430896, CVE-2026-100243) - Stored XSS in WikiSEO author and image props when viewing on action=info https://gerrit.wikimedia.org/r/q/Iff6ef320017649750e5c6723a91ee298eb97a408 CentralAuth + (T432789, CVE-2026-100244) - CentralAuth exposes locally suppressed block associations via public API and UI https://gerrit.wikimedia.org/r/1346069 Wikibase + (T432877, CVE-2026-100245) - Stored XSS on Special:SetSiteLink via unescaped system message https://gerrit.wikimedia.org/r/1346070 UserPageViewTracker + (T432836, CVE-2026-102796) - Unauthenticated SQL injection (credential disclosure) via Special:UserPageViewTracker https://gerrit.wikimedia.org/r/q/I43c5360c2f78611351b5dc4c90a80e627d51deaf ExternalData + (T434961, CVE-2026-100382) - Unauthenticated RCE through wikitext https://gerrit.wikimedia.org/r/c/mediawiki/extensions/ExternalData/+/1326012 TemplateSandbox + (T430596, CVE-2026-100376) - XSS through a sandbox prefix that belongs to another user https://gerrit.wikimedia.org/r/q/I6630b9915f640bf75c8570165eb8728bd7a2c07a Translate + (T433070, CVE-2026-100378) - Missing permission check in the sandbox doRemind action https://gerrit.wikimedia.org/r/q/I9b74c849b223f18955b42779f5ffbd1e051e415c UploadWizard + (T434619, CVE-2026-100381) - DOM XSS in Flickr collection and set titles https://gerrit.wikimedia.org/r/q/Iba914c0d7e86f9342ee9cecde3bee0806ec90c84 Wikibase + (T434549, CVE-2026-100380) - Reflected XSS in Special:SetLabel language validation https://gerrit.wikimedia.org/r/q/I7407f9748d72161ce25ad0ba2446869bb1776857 WikiLambda + (T430601, CVE-2026-100377) - Revision-deleted content is shown through action=edit and Special:ViewAbstract https://gerrit.wikimedia.org/r/q/Ie9fe27978ea78489ec763168bbda6cfb66c6b001 WikiLambda + (T434967, CVE-2026-100383) - Stored i18n XSS in the VisualEditor integration https://gerrit.wikimedia.org/r/q/I043febf01c58e0c3066c7a094c03348b31e14653 Wikipedia Android App + (T433832, CVE-2026-100379) - Cross-request disclosure of CentralAuth cookies https://github.com/wikimedia/apps-android-wikipedia/pull/6768 Maps + (GHSA-rg4f-xvhj-mw22) - XSS through unsanitized KML file https://github.com/ProfessionalWiki/Maps/security/advisories/GHSA-rg4f-xvhj-mw22 WikiLambda + (T435085, CVE-2026-96872) - WikiLambda public function execution bypasses the unsaved-code permission through nested Z825 compositions https://gerrit.wikimedia.org/r/c/mediawiki/extensions/WikiLambda/+/1326392 CirrusSearch + (T435234, CVE-2026-96873) - CirrusSearch debug explain reflected XSS https://gerrit.wikimedia.org/r/c/mediawiki/extensions/CirrusSearch/+/1344368 Cargo + (T435207, CVE-2026-96874) - Stored XSS in Cargo Drilldown tab names https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1328631 Cargo + (T435206, CVE-2026-96875) - Reflected XSS in Cargo Drilldown hierarchy filters https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1328629 Cargo + (T435121, CVE-2026-96876) - Anonymous reflected XSS in CargoExport invalid-alias errors https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1328630 Cargo + (T434977, CVE-2026-96877) - Cargo Drilldown full-text search reflected XSS https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1328628 Cargo + (T434784, CVE-2026-96878) - Cargo Exhibit field alias allows stored XSS https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1328627 FlaggedRevs + (T433020, CVE-2026-96879) - "Checked by" label in page history should not be shown if the underlying review log entry is suppressed https://gerrit.wikimedia.org/r/c/mediawiki/extensions/FlaggedRevs/+/1344737 Semantic MediaWiki + (GHSA-cx86-7xwp-w9wf, CVE-2026-77616) - Reflected XSS via a forged cursor pagination token https://github.com/SemanticMediaWiki/SemanticMediaWiki/security/advisories/GHSA-cx86-7xwp-w9wf https://github.com/SemanticMediaWiki/SemanticMediaWiki/releases/tag/7.2.0 Semantic MediaWiki + (GHSA-q5fm-9mx6-44f4, CVE-2026-77610) - Query debug output XSS (DebugFormatter) https://github.com/SemanticMediaWiki/SemanticMediaWiki/security/advisories/GHSA-q5fm-9mx6-44f4 https://github.com/SemanticMediaWiki/SemanticMediaWiki/releases/tag/7.2.0 Semantic MediaWiki + (GHSA-hw3m-8j5x-94ff, CVE-2026-77609) - Open redirect in Special:URIResolver https://github.com/SemanticMediaWiki/SemanticMediaWiki/security/advisories/GHSA-hw3m-8j5x-94ff https://github.com/SemanticMediaWiki/SemanticMediaWiki/releases/tag/7.2.0 Semantic MediaWiki + (GHSA-59xw-qv23-j3rc, CVE-2026-77608) - Reflected XSS in Special:SearchByProperty https://github.com/SemanticMediaWiki/SemanticMediaWiki/security/advisories/GHSA-59xw-qv23-j3rc https://github.com/SemanticMediaWiki/SemanticMediaWiki/releases/tag/7.2.0 Semantic MediaWiki + (GHSA-7xv3-gf2g-498h, CVE-2026-77607) - Special:Ask table sep parameter reflected XSS https://github.com/SemanticMediaWiki/SemanticMediaWiki/security/advisories/GHSA-7xv3-gf2g-498h https://github.com/SemanticMediaWiki/SemanticMediaWiki/releases/tag/7.2.0 Semantic MediaWiki + (GHSA-3jp5-3h47-28qf, CVE-2026-77606) - Reflected XSS in Special:Ask plain table headers https://github.com/SemanticMediaWiki/SemanticMediaWiki/security/advisories/GHSA-3jp5-3h47-28qf https://github.com/SemanticMediaWiki/SemanticMediaWiki/releases/tag/7.2.0 Wikibase + (T435210, CVE-2026-103441) - Unauthenticated arbitrary file deletion through Wikibase serialized entity parsing https://gerrit.wikimedia.org/r/q/Id35bf747e48370e474d9b9444bd7520b24836e8d CentralAuth + (T435624, CVE-2026-103442) - MergeAccount PHP object injection via session-key substitution https://gerrit.wikimedia.org/r/q/I9c59e5c3f217c1eaa02934a076604049bac2b025 Collection (aka Book) + (T435822, CVE-2026-103443) - API permits session-seeded javascript URL XSS https://gerrit.wikimedia.org/r/q/I51d973d4ace99fb6e584296f296efb0ff50339ce WikiForum + (T414227, CVE-2026-103444) - Stored XSS through system messages in WikiForum https://gerrit.wikimedia.org/r/q/I7849ef0f9c3eff48fd63e47e5b8affc3b25bb4dd PageForms + (T435622, CVE-2026-103445) - Stored XSS through PageForms #autoedit redirect links https://gerrit.wikimedia.org/r/q/I4ace525a1c1760ecdd1d770380606d9960d3e644 WikiLambda + (T435086, CVE-2026-103446) - WikiLambda exposes anonymous execution of unsaved Abstract Wikipedia fragments https://gerrit.wikimedia.org/r/q/If2c05b109672fc65f63372f86c768859dc6639fd ReadingLists + (T435863, CVE-2026-103437) - Imported canonical URL XSS https://gerrit.wikimedia.org/r/q/I9a724c05b2a55845007512422362e02ed8cf44b0 Wikistories + (T182213, CVE-2026-103438) - Various rawParams() and escaped() updates to prevent XSS https://gerrit.wikimedia.org/r/q/Iad1281879723eba73e4338a00d5ff35c6eed0c3e Wikibase + (T182213, CVE-2026-103439) - Various rawParams() and escaped() updates to prevent XSS https://gerrit.wikimedia.org/r/q/Ie7a35b211565148e0cae437a4a8c41633b81f1b3 PageTriage + (T435623, CVE-2026-103440) - pagetriagelist discloses suppressed reviewer usernames https://gerrit.wikimedia.org/r/q/I4bdd5f5be95ed5d02c504784fb31da4e5de59da6 CommonsMetadata + (T435999, CVE-2026-103584) - attacker-controlled javascript license URL via XSS https://gerrit.wikimedia.org/r/q/I4d4910f2d761fee96a3dcea01eb245c717ef9be5 MediaSearch + (T435999, CVE-2026-103585) - attacker-controlled javascript license URL via XSS https://gerrit.wikimedia.org/r/q/I79e8200289bd120c3c971ba830776eaae779bb99 The Wikimedia Security Team recommends updating these extensions and/or skins to the current master branch or relevant, supported release branch [2] as soon as possible. Some of the referenced Phabricator tasks above _may_ still be private. Unfortunately, when security issues are reported, sometimes sensitive information is exposed and since Phabricator is historical, we cannot make these tasks public without exposing this sensitive information. If you have any additional questions or concerns regarding this update, please feel free to contact [email protected] or file a security task within Phabricator [3]. CVE JSON references can be found on Gitlab [4]. [1] https://phabricator.wikimedia.org/T429207 [2] https://www.mediawiki.org/wiki/Version_lifecycle [3] https://www.mediawiki.org/wiki/Reporting_security_bugs [4] https://gitlab.wikimedia.org/repos/security/wikimedia-cve-assignments _______________________________________________ MediaWiki-announce mailing list -- [email protected] To unsubscribe send an email to [email protected]
