CVE-2025-32699: Potential javascript injection attack enabled by Unicode normalization in Action API
Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid.This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1; Parsoid: before 0.16.5, 0.19.2, 0.20.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32699?
CVE-2025-32699 has a critical severity level due to the potential for unauthorized access and manipulation of content in affected MediaWiki and Parsoid versions.
How do I fix CVE-2025-32699?
To fix CVE-2025-32699, upgrade MediaWiki to version 1.39.12 or later, and Parsoid to version 0.16.5 or later.
What versions are affected by CVE-2025-32699?
CVE-2025-32699 affects MediaWiki versions prior to 1.39.12, 1.42.6, and 1.43.1, as well as Parsoid versions before 0.16.5, 0.19.2, and 0.20.2.
Is CVE-2025-32699 a remote code execution vulnerability?
CVE-2025-32699 is not classified as a remote code execution vulnerability, but it can lead to content manipulation and unauthorized data access.
Who is affected by CVE-2025-32699?
Any users or organizations running vulnerable versions of MediaWiki or Parsoid are affected by CVE-2025-32699.