CVE-2025-6590: Complete content leak of private wikis due to PasswordReset Wikitext injection in error message
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLUserTextField.Php.
This issue affects MediaWiki: from through 1.39.12, 1.42.76 1.43.1, 1.44.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6590?
CVE-2025-6590 is considered a high severity vulnerability due to the potential for complete content leakage of private wikis.
How do I fix CVE-2025-6590?
To mitigate CVE-2025-6590, update Wikimedia Foundation MediaWiki to a version greater than 1.39.12.
What causes CVE-2025-6590?
CVE-2025-6590 is caused by a PasswordReset Wikitext injection in error messages that can expose sensitive information.
Which versions of MediaWiki are affected by CVE-2025-6590?
CVE-2025-6590 affects MediaWiki versions from 1.39.0 up to and including 1.39.12.
Who is impacted by CVE-2025-6590?
Users of private wikis on affected versions of Wikimedia Foundation MediaWiki are at risk due to CVE-2025-6590.