CVE-2025-6589: With MultiBlocks enabled and a user who is suppressed via a MultiBlock, a user without 'hideuser' can see the hidden username in the BlockList
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/specials/pagers/BlockListPager.Php.
This issue affects MediaWiki: >= 1.42.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6589?
CVE-2025-6589 is classified as a medium severity vulnerability due to its potential for user information exposure.
How do I fix CVE-2025-6589?
To fix CVE-2025-6589, update your MediaWiki installation to version 1.42.1 or later where the vulnerability is addressed.
Who is affected by CVE-2025-6589?
CVE-2025-6589 affects users of Wikimedia Foundation MediaWiki version 1.42.0 and earlier with MultiBlocks enabled.
What types of users are impacted by CVE-2025-6589?
Users with the ability to view the BlockList without the 'hideuser' permission can see hidden usernames in the BlockList due to CVE-2025-6589.
Is there a workaround for CVE-2025-6589?
Currently, there are no specific workarounds for CVE-2025-6589, and updating to the latest version is recommended.