Junglewise Threat Intelligence

CVE-2026-58032: Wikimedia Foundation MediaWiki XSS in mediawiki.Api component

CVE-2026-58032 · Severity: info · CVSS 5.3 · Published 2026-07-01

Technologies: Wikimedia Foundation MediaWiki. Vendors: Wikimedia Foundation.

Executive brief

A cross-site scripting (XSS) vulnerability exists in MediaWiki, the software used to power Wikipedia and many other collaborative websites. This flaw allows an attacker to potentially execute malicious scripts in the browser of a user who visits a compromised page. Such an attack could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in MediaWiki due to improper neutralization of input during web page generation. The flaw is specifically located within the 'resources/src/mediawiki.Api/index.js' component. An unauthenticated remote attacker can exploit this by tricking a user into interacting with a specially crafted link or page, leading to the execution of arbitrary JavaScript in the context of the victim's browser session. This issue is tracked as CWE-79 and has been addressed in versions 1.46.0, 1.45.4, 1.44.6, and 1.43.9.

Affected products

  • Wikimedia Foundation MediaWiki Versions before 1.46.0, 1.45.4, 1.44.6, 1.43.9

Timeline

  • 2026-07-01: disclosed
  • 2026-07-01: advisory

References

Related threats