Impact
The EmbedVideo extension adds a #ev parser function and tags that allow embedding videos from multiple services into MediaWiki pages. Prior to version 4.1.0, the factory function EmbedServiceFactory::newFromName could interpolate an attacker‑controlled, unknown service name into an exception message, and the resulting text was returned as raw HTML via the extension's isHtml output path without neutralization. Both the #ev parser function and the evl parser tag can trigger this error path. A user with edit rights to a wiki page can therefore inject stored HTML or JavaScript into the error output, causing code to execute in the browser of any visitor who renders the affected page. The bug is fixed in version 4.1.0.
Affected Systems
All installations of the StarCitizenWiki mediawiki‑extensions‑EmbedVideo extension with a version older than 4.1.0 are vulnerable. The issue was publicly addressed in release 4.1.0, so any MediaWiki site still using an earlier release is at risk, regardless of how the extension is configured. Sites that use the #ev or evl parser tags are particularly exposed, as those are the entry points described in the advisory.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity impact. The EPSS score is < 1%, and the flaw is not listed in CISA's KEV catalog. Attackers only need permission to edit a page; they can insert a malicious service name that triggers the error path. Once injected, the stored script is executed in the browser of every visitor who renders the corrupted page, enabling attacker‑controlled actions such as session theft, defacement, or further lateral movement within the wiki environment. Given the popularity of MediaWiki in community sites, the potential attack surface is broad.
OpenCVE Enrichment
Github GHSA