Junglewise Threat Intelligence

CVE-2026-34095: Wikimedia Foundation MediaWiki incorrect Content-Type in ActionEntryPoint

CVE-2026-34095 · Severity: medium · CVSS 6.1 · Published 2026-05-11

Technologies: Wikimedia Foundation MediaWiki. Vendors: Wikimedia Foundation.

Executive brief

A vulnerability in MediaWiki, the software powering Wikipedia and other wikis, could allow attackers to bypass security protections that prevent malicious code from running in a user's browser. By tricking a user into clicking a specially crafted link to their own user page, an attacker could potentially execute unauthorized scripts within the context of that user's session. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.

Technical details

A vulnerability exists in MediaWiki's ActionEntryPoint and FauxResponse components where the 'action=raw' parameter, when used with 'Special:Mypage' subpage titles, fails to correctly apply the requested Content-Type header (e.g., text/javascript). Instead, the application responds with 'text/html'. This occurs because ActionEntryPoint resolves special page redirects using a DerivativeRequest that does not properly propagate headers set by RawAction. An attacker can exploit this by placing malicious content on a victim's user subpage (which may be editable by others depending on wiki configuration) and social engineering the victim into visiting a crafted URL. This results in the browser rendering the page content as arbitrary HTML/JavaScript in the victim's session. The issue is fixed in versions 1.43.7, 1.44.4, and 1.45.2.

Affected products

  • Wikimedia Foundation MediaWiki before 1.43.7, 1.44.4, 1.45.2

Timeline

  • 2026-03-06: disclosed: Issue reported internally via Phabricator.
  • 2026-05-11: advisory: CVE-2026-34095 published.

References

Related threats