CVE-2026-58032: mw.Api.getErrorMessage() may return injected HTML if used without errorformat=html
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files resources/src/mediawiki.Api/index.Js.
This issue affects MediaWiki: from before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58032?
The severity of CVE-2026-58032 is classified as medium with a CVSS score of 5.3.
What types of systems are affected by CVE-2026-58032?
CVE-2026-58032 affects versions of MediaWiki prior to 1.46.0, specifically 1.45.4, 1.44.6, and earlier.
How do I fix CVE-2026-58032?
To fix CVE-2026-58032, upgrade your MediaWiki installation to a version of 1.46.0 or later.
What exploit does CVE-2026-58032 allow an attacker to perform?
CVE-2026-58032 allows an attacker to exploit an XSS vulnerability through improper handling of injected HTML.
What component of MediaWiki is primarily impacted by CVE-2026-58032?
The mw.Api.getErrorMessage() function in MediaWiki is primarily impacted by CVE-2026-58032.