CVE-2026-39839: Stored XSS through URLs in Cargo's map format
Published Apr 7, 2026
·Updated
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.
Affected Software
2 affected components
Wikimedia Foundation Mediawiki - Cargo Extension<3.8.7
MediaWiki Cargo<3.8.7
Remediation
Event History
Apr 7, 2026
CVE Published
via MITRE·07:29 PM
Data Sourced
via MITRE·07:29 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-39839?
CVE-2026-39839 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2026-39839?
To fix CVE-2026-39839, upgrade MediaWiki - Cargo Extension to version 3.8.7 or later.
3
What kind of attack can CVE-2026-39839 enable?
CVE-2026-39839 can enable an attacker to execute arbitrary JavaScript in the context of a user’s session through stored XSS.
4
Which versions of MediaWiki are affected by CVE-2026-39839?
CVE-2026-39839 affects MediaWiki - Cargo Extension versions before 3.8.7.
5
Is user input the cause of CVE-2026-39839?
Yes, CVE-2026-39839 results from improper neutralization of script-related HTML tags in user input URLs.