CVE-2025-67481: mw.message(…).parse() doesn't output safe HTML, but it's being used as if it does
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.JqueryMsg/mediawiki.JqueryMsg.Js.
This issue affects MediaWiki: from before 1.39.16, 1.43.6, 1.44.3, 1.45.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67481?
The severity of CVE-2025-67481 is high due to its risk of allowing Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-67481?
To fix CVE-2025-67481, update the MediaWiki software to version 1.39.16 or higher.
What type of vulnerability is CVE-2025-67481?
CVE-2025-67481 is classified as an Improper Neutralization of Input During Web Page Generation, specifically leading to Cross-site Scripting (XSS).
Which versions of MediaWiki are affected by CVE-2025-67481?
CVE-2025-67481 affects MediaWiki versions prior to 1.39.16.
What are the potential impacts of CVE-2025-67481?
The potential impacts of CVE-2025-67481 include unauthorized access to user data and the ability for attackers to execute scripts in the context of the affected user's session.