Junglewise Threat Intelligence

CVE-2026-58030: Wikimedia Foundation SyntaxHighlight_GeSHi XSS in SyntaxHighlight.php

CVE-2026-58030 · Severity: info · CVSS 5.3 · Published 2026-07-01

Vendors: Wikimedia Foundation.

Executive brief

The SyntaxHighlight_GeSHi extension, used by MediaWiki to display formatted code snippets, contains a security flaw that allows for cross-site scripting (XSS). An attacker with basic user permissions could potentially inject malicious scripts into web pages viewed by other users. This could lead to unauthorized actions being performed in the context of a user's session or the theft of sensitive information.

Technical details

A cross-site scripting (XSS) vulnerability exists in the Wikimedia Foundation SyntaxHighlight_GeSHi extension, specifically within the 'includes/SyntaxHighlight.php' component. The flaw stems from improper neutralization of input during web page generation, allowing an attacker to inject malicious scripts. The attack vector is network-based and requires low privileges (PR:L), though the CNA indicates no user interaction (UI:N) is required for the specific CVSS 4.0 vector provided. The issue is addressed in versions 1.46.0, 1.45.4, 1.44.6, and 1.43.9.

Affected products

  • Wikimedia Foundation SyntaxHighlight_GeSHi Before 1.46.0, 1.45.4, 1.44.6, 1.43.9

Timeline

  • 2026-07-01: advisory: Initial disclosure of CVE-2026-58030

References