CVE-2025-67479: Magic word replacement in legacy parser allows using reserved data attributes through wikitext
Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Cite. This vulnerability is associated with program files includes/Parser/CoreParserFunctions.Php, includes/Parser/Sanitizer.Php.
This issue affects MediaWiki: from before 1.39.14, 1.43.4, 1.44.1; Cite: from before 1.39.14, 1.43.4, 1.44.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67479?
CVE-2025-67479 is rated as a medium severity vulnerability.
How do I fix CVE-2025-67479?
To fix CVE-2025-67479, update to MediaWiki version 1.39.15 or later, or 1.43.5 or later, or 1.44.2 or later.
What products are affected by CVE-2025-67479?
CVE-2025-67479 affects Wikimedia Foundation MediaWiki and Wikimedia Foundation Cite versions prior to the specified updates.
Can CVE-2025-67479 allow unauthorized access?
Yes, CVE-2025-67479 can potentially allow the use of reserved data attributes through wikitext, leading to unauthorized data manipulation.
What components are involved in the CVE-2025-67479 vulnerability?
CVE-2025-67479 is associated with the CoreParserFunctions.Php and Sanitizer.Php files in legacy parser.