Junglewise Threat Intelligence

CVE-2026-14363: Wikimedia MediaWiki SQL injection in Cargo extension Special:Drilldown

CVE-2026-14363 · Severity: info · CVSS 6.9 · Published 2026-07-01

Executive brief

The Cargo extension for MediaWiki, which allows for the storage and querying of data within wiki pages, contains a security vulnerability that could allow unauthorized users to access sensitive database information. By sending specially crafted web requests to the 'Special:Drilldown' page, an attacker can bypass intended data filters to view or extract data they are not authorized to see. This issue affects organizations using MediaWiki with the Cargo extension enabled, potentially leading to data leaks or exposure of internal wiki metadata.

Technical details

An SQL injection vulnerability exists in the Cargo extension for MediaWiki within the 'Special:Drilldown' page. The root cause is the improper neutralization of user-supplied input in the `checkSQL()` function within `CargoAppliedFilter.php`, where input is concatenated directly into SQL strings instead of using parameterized queries or database abstractions. An unauthenticated remote attacker can exploit this by providing malicious values to date-related parameters (e.g., `_lower_DATEFIELDNAME`), allowing them to manipulate the resulting SQL query logic. This can be used to exfiltrate sensitive data from the database. The issue has been addressed in versions 1.43.9, 1.44.6, and 1.45.4 by implementing better input validation and casting.

Affected products

  • The Wikimedia Foundation MediaWiki - Cargo Extension before 1.43.9, 1.44.6, 1.45.4

Timeline

  • 2026-04-09: disclosed: Vulnerability reported to Wikimedia Phabricator
  • 2026-04-10: patched: Initial fix committed to Gerrit repository
  • 2026-07-01: advisory: CVE published and Phabricator task made public

References