Junglewise Threat Intelligence

CVE-2026-58031: Wikimedia Foundation MediaWiki XSS in ApiSandboxLayout

CVE-2026-58031 · Severity: info · CVSS 0 · Published 2026-07-01

Technologies: Wikimedia Foundation MediaWiki. Vendors: Wikimedia Foundation.

Executive brief

MediaWiki, the software powering Wikipedia and many other wikis, contains a security flaw in its API Sandbox tool. This tool is used by developers to test how the website communicates with other applications. An attacker could potentially use this flaw to run unauthorized scripts in a user's browser, though the reported impact is minimal and requires the attacker to have a user account.

Technical details

A cross-site scripting (XSS) vulnerability exists in MediaWiki's ApiSandboxLayout.js component. The flaw is caused by improper neutralization of input during web page generation within the Special:ApiSandbox interface. An attacker with basic user privileges (PR:L) could potentially inject malicious scripts that execute in the context of another user's session, provided there is user interaction (UI:P). The vulnerability specifically affects versions 1.46.0-rc.0 through 1.46.0. While the CNA has assigned a CVSS score of 0.0, the vulnerability is tracked as CWE-79.

Affected products

  • Wikimedia Foundation MediaWiki 1.46.0-rc.0 to 1.46.0

Timeline

  • 2026-07-01: advisory: NVD publication date

References

Related threats