Junglewise Threat Intelligence

CVE-2026-58521: Wikimedia MediaWiki Cargo Extension SQL injection in Special:Drilldown

CVE-2026-58521 · Severity: info · CVSS 6.9 · Published 2026-07-01

Executive brief

The Cargo extension for MediaWiki, which allows users to store and query data within wiki pages, contains a security flaw in its data filtering system. An attacker can exploit this to run unauthorized database commands, potentially leading to the theft of sensitive user tokens or causing the website to become slow and unresponsive. This could allow an attacker to take over user accounts or disrupt the wiki's operations.

Technical details

A SQL injection vulnerability exists in the Cargo extension for MediaWiki due to improper neutralization of the year range filter in the Special:Drilldown component. The vulnerability occurs because the extension fails to sanitize numeric year values before inserting them into a SELECT query's WHERE clause. An unauthenticated remote attacker can exploit this by providing a specially crafted year range (e.g., using boolean logic or SLEEP commands) to perform time-based blind SQL injection. Successful exploitation can lead to the exfiltration of sensitive data from the database, such as user_tokens, or a denial-of-service condition by exhausting database threads. The issue is fixed in versions 1.43.9, 1.44.6, and 1.45.4.

Affected products

  • The Wikimedia Foundation MediaWiki - Cargo Extension before 1.43.9, 1.44.6, 1.45.4

Timeline

  • 2026-06-05: disclosed: Vulnerability reported and task created in Phabricator.
  • 2026-06-08: patched: Fix merged into the master branch.
  • 2026-07-01: advisory: CVE published and Phabricator task made public.

References