CVE-2026-103048: Open Redirect in Special:Book
Published Sep 29, 2026
·Updated
URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - Collection extension allows Fake the Source of Data.
This issue affects Mediawiki - Collection extension: before 1.46.1, 1.45.5, 1.43.10.
Affected Software
1 affected component
Wikimedia Foundation MediaWiki Collection extension<1.46.1, <1.45.5, <1.43.10
Event History
Sep 29, 2026
CVE Published
via MITRE·11:04 PM
Data Sourced
via MITRE·11:04 PM
DescriptionWeakness
Sep 30, 2026
Data Sourced
via NVD·12:16 AM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments need to be updated?
MediaWiki installations using the Collection extension are affected if they run a version earlier than 1.46.1, 1.45.5, or 1.43.10.
2
What is the security impact of exploiting this issue?
An attacker can cause URL redirection to an untrusted site, enabling spoofing of the apparent source of data.