CVE-2025-61653: Extension:TextExtracts does not check for authorizeRead when returning extracts
Published Feb 3, 2026
·Updated
Vulnerability in Wikimedia Foundation TextExtracts. This vulnerability is associated with program files includes/ApiQueryExtracts.Php.
This issue affects TextExtracts: from before 1.39.14, 1.43.4, 1.44.1.
Affected Software
1 affected component
Wikimedia Foundation TextExtracts>1.39.14, <1.43.4, <1.44.1
Event History
Feb 3, 2026
CVE Published
via MITRE·12:57 AM
Data Sourced
via MITRE·12:57 AM
Description
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-61653?
CVE-2025-61653 has a medium severity rating due to its potential to expose unauthorized data.
2
How do I fix CVE-2025-61653?
To fix CVE-2025-61653, update to version 1.39.14, 1.43.4, or 1.44.1 of the Wikimedia Foundation TextExtracts.
3
What systems are affected by CVE-2025-61653?
CVE-2025-61653 affects versions of Wikimedia Foundation TextExtracts prior to 1.39.14, 1.43.4, and 1.44.1.
4
What kind of attack does CVE-2025-61653 expose systems to?
CVE-2025-61653 exposes systems to unauthorized reading of extract data, potentially compromising sensitive information.
5
Who reported CVE-2025-61653?
CVE-2025-61653 was reported in connection with the Wikimedia Foundation's ongoing security assessments.