CVE-2025-62699: Special:Translate tool does not use the correct IP and User-Agent in the CheckUser tool
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Translate Extension allows Footprinting. Translate extension appears to use jobs to make edits to translation pages. This causes the CheckUser tool to log the wrong IP and User-Agent making these edits un-auditable via the CheckUser tool.This issue affects Mediawiki - Translate Extension: from master before 1.39.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62699?
CVE-2025-62699 is considered a medium severity vulnerability due to the exposure of sensitive information.
How does CVE-2025-62699 affect users of the Mediawiki - Translate Extension?
CVE-2025-62699 affects users by potentially allowing unauthorized actors to footprint through the incorrect logging of IP addresses.
How do I fix CVE-2025-62699?
To fix CVE-2025-62699, users should update the Mediawiki - Translate Extension to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-62699?
Anyone using the Mediawiki - Translate Extension version 1.39 or earlier is vulnerable to CVE-2025-62699.
What is the cause of CVE-2025-62699?
CVE-2025-62699 is caused by the Translate Extension misusing jobs to edit translation pages, leading to incorrect IP logging.