CVE 8.6 HIGH

Star Citizen EmbedVideo Extension Stored XSS through wikitext caused by usage of non-reserved data attributes_CVE-2025-59839

8.6 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Description

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. In versions 4.0.0 and prior, the EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for stored XSS through wikitext. This issue has been patched via commit 4e075d3.

Basic Information

ID CVE-2025-59839
Source GitHub_M
Published Sep 25, 2025 at 13:56
Modified Sep 25, 2025 at 14:19

Affected Product

Vendor StarCitizenWiki
Product mediawiki-extensions-EmbedVideo
Version <= 4.0.0
Affected Versions StarCitizenWiki mediawiki-extensions-EmbedVideo <= 4.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.