Junglewise Threat Intelligence

CVE-2026-58035: Wikimedia Foundation MediaWiki XSS in SpecialBlock.Vue

CVE-2026-58035 · Severity: info · CVSS 0 · Published 2026-07-01

Technologies: Wikimedia Foundation MediaWiki. Vendors: Wikimedia Foundation.

Executive brief

MediaWiki, the software powering Wikipedia and many other wikis, contains a security flaw in its user blocking interface. An attacker with high-level administrative privileges could potentially execute malicious scripts in the browser of another user. While the risk is limited by the high level of access required, it could lead to unauthorized actions being performed on behalf of other administrators.

Technical details

A Cross-site Scripting (XSS) vulnerability exists in MediaWiki within the SpecialBlock.Vue component (resources/src/mediawiki.Special.Block/SpecialBlock.Vue). The flaw stems from improper neutralization of input during web page generation. An attacker with high privileges (PR:H) can exploit this over the network, though it requires some level of user interaction (UI:P). Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session. The vulnerability affects versions starting from 1.46.0-rc.0 and is addressed in version 1.46.0.

Affected products

  • Wikimedia Foundation MediaWiki 1.46.0-rc.0 to 1.46.0

Timeline

  • 2026-07-01: advisory: CVE-2026-58035 published by Wikimedia Foundation

References

Related threats