CVE-2026-100377: Revision-deleted pages can be viewed through WikiLambda's action=edit and Special:ViewAbstract
Published Sep 25, 2026
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Excavation.
This issue affects Mediawiki - WikiLambda Extension: 1.47.0-alpha. The issue has been remediated on the master branch.
Affected Software
1 affected component
Wikimedia Foundation MediaWiki - WikiLambda Extension=1.47.0-alpha
Event History
Sep 25, 2026
CVE Published
via MITRE·08:47 PM
Data Sourced
via MITRE·08:47 PM
DescriptionWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are known to be affected?
The issue is identified in WikiLambda Extension version 1.47.0-alpha. The available data states that it has been remediated on the master branch.
2
What information could be exposed?
Revision-deleted pages may be viewable through WikiLambda's action=edit and Special:ViewAbstract interfaces.