Junglewise Threat Intelligence

CVE-2026-58518: Wikimedia MediaWiki CSRF in RedirectManager extension API

CVE-2026-58518 · Severity: info · CVSS 6.9 · Published 2026-07-01

Vendors: Wikimedia Foundation.

Executive brief

The RedirectManager extension for MediaWiki, which allows users to manage page redirects, contains a security flaw that could allow an attacker to trick a logged-in administrator into performing unintended actions. Specifically, an attacker could force a user's browser to create unauthorized page redirects without their knowledge. This could be used to disrupt site navigation or redirect users to malicious external websites, potentially damaging the site's reputation and user trust.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the RedirectManager extension for MediaWiki due to the lack of CSRF token validation in its API endpoint. The `Api.php` component fails to override the `needsToken()` method, allowing state-changing actions (creating redirects) to be executed via simple POST requests without a valid session-specific token. An attacker can exploit this by inducing an authenticated user to visit a malicious webpage that triggers a background request to the vulnerable wiki. This issue is resolved in version 1.3.3 by requiring a CSRF token for API interactions.

Affected products

  • Wikimedia Foundation MediaWiki RedirectManager Extension before 1.3.3

Timeline

  • 2026-04-19: disclosed: Issue reported and task created in Phabricator
  • 2026-04-20: patched: Fix merged into master branch and version 1.3.3 released
  • 2026-07-01: advisory: CVE published and Phabricator task made public

References