Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.9 PHP packages GHSA-v65j-hff3-753c CVE-2026-57440 PKSA-1f7b-5f9b-ggt9

Stored XSS in MediaWiki EmbedVideo Extension (CVE-2026-57440)

The EmbedVideo MediaWiki extension, versions up to and including 4.0.0, fails to sanitize video URLs when the $wgEmbedVideoRequireConsent setting is disabled, allowing attackers to inject HTML/JavaScript via a malformed video URL or ID. Version 4.1.0 fixes the issue.

Synthesized by AI from 3 sources · updated 1 hour ago

AI summary

A cross-site scripting vulnerability has been identified in EmbedVideo, a MediaWiki extension used to embed video clips from external video sharing services via the #ev parser function and related parser tags. The issue affects installations where a non-default configuration option, $wgEmbedVideoRequireConsent, has been disabled. This briefing summarizes what is known about the vulnerability, who is affected, and what action to take.

What happened

EmbedVideo, a MediaWiki extension for embedding videos through the #ev parser function and parser tags, contains a cross-site scripting vulnerability tracked as CVE-2026-57440. When the configuration setting $wgEmbedVideoRequireConsent is disabled (this is not the default setting), video URLs supplied to the extension are inserted into an iframe's src attribute without proper sanitization.

Technical cause

The vulnerability is classified as CWE-79, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). A malformed URL or video ID can be crafted to break out of the iframe src attribute using double quotes, allowing an attacker to inject arbitrary HTML or JavaScript into the resulting page. This occurs only when $wgEmbedVideoRequireConsent is disabled, since this setting otherwise affects how video URLs are processed before rendering.

Why it matters

The vulnerability has a CVSS base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), indicating it can be exploited remotely over the network, requires no privileges, requires no user interaction, and has a low attack complexity. The impact is rated high for confidentiality. Because the injected content is persisted on a wiki page (stored XSS), it can affect any visitor who later views the page containing the malicious embed.

Who is affected

This affects MediaWiki sites running the starcitizenwiki/embedvideo extension (versions up to and including 4.0.0) where the non-default configuration option $wgEmbedVideoRequireConsent has been disabled. Sites running with the default configuration (consent enabled) are not described as affected in the available facts.

Affected versions

All versions from the initial release up to and including 4.0.0 of starcitizenwiki/embedvideo are affected.

Fixes and mitigation

Version 4.1.0 of starcitizenwiki/embedvideo contains a patch for this vulnerability. Site operators should update to 4.1.0 or later.

Recommended action

Update the EmbedVideo extension to version 4.1.0 or later as soon as possible. If an immediate update is not feasible, ensure $wgEmbedVideoRequireConsent remains enabled (the default setting), as the vulnerability only manifests when this option has been disabled.

PatchBriefing score

4.9 / 10 · Medium

Official CVSS: 7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Why this score

PatchBriefing assigns this advisory a score of 4.9 out of 10. This reflects the CVSS base score of 7.5, which contributes the largest portion of the score due to the vulnerability being remotely exploitable without authentication or user interaction and having a high confidentiality impact. Additional minor contributions come from the unauthenticated, remote nature of the attack and the absence of required user interaction. There is no evidence of known exploitation in the wild, no public exploit code, and a fix is already available, all of which keep the overall score moderate rather than critical. No EPSS score contribution was applied as EPSS data in the source items was not consistently supplied in the scoring factors.

Affected versions

starcitizenwiki/embedvideo <= 4.0.0
vulnerable
starcitizenwiki/embedvideo <=4.0.0
vulnerable
≥ 4.1.0
patched

Reported fixes

Version 4.1.0 of starcitizenwiki/embedvideo contains a patch for this vulnerability. Site operators should update to 4.1.0 or later.

How this was built

3 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • Packagist Security Advisories registry
  • NVD (NIST) database
Unified report
Stored XSS in MediaWiki EmbedVideo Extension (CVE-2026-57440)
1 article · 3 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email