Description
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedServiceFactory::newFromName in includes/EmbedService/EmbedServiceFactory.php interpolates an attacker-controlled unknown service name into exception text, and includes/EmbedVideo.php returns that text as HTML through the isHtml output path without neutralization. Both the #ev parser function and the evl parser form can reach this error path. A user able to edit a wiki page can inject stored HTML or JavaScript into the error output, causing code to execute in the wiki origin for visitors who render the page. This issue is fixed in version 4.1.0.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Upgrade Extension
AI Analysis

Impact

The EmbedVideo extension adds a #ev parser function and tags that allow embedding videos from multiple services into MediaWiki pages. Prior to version 4.1.0, the factory function EmbedServiceFactory::newFromName could interpolate an attacker‑controlled, unknown service name into an exception message, and the resulting text was returned as raw HTML via the extension's isHtml output path without neutralization. Both the #ev parser function and the evl parser tag can trigger this error path. A user with edit rights to a wiki page can therefore inject stored HTML or JavaScript into the error output, causing code to execute in the browser of any visitor who renders the affected page. The bug is fixed in version 4.1.0.

Affected Systems

All installations of the StarCitizenWiki mediawiki‑extensions‑EmbedVideo extension with a version older than 4.1.0 are vulnerable. The issue was publicly addressed in release 4.1.0, so any MediaWiki site still using an earlier release is at risk, regardless of how the extension is configured. Sites that use the #ev or evl parser tags are particularly exposed, as those are the entry points described in the advisory.

Risk and Exploitability

The CVSS score is 7.5, indicating a high severity impact. The EPSS score is < 1%, and the flaw is not listed in CISA's KEV catalog. Attackers only need permission to edit a page; they can insert a malicious service name that triggers the error path. Once injected, the stored script is executed in the browser of every visitor who renders the corrupted page, enabling attacker‑controlled actions such as session theft, defacement, or further lateral movement within the wiki environment. Given the popularity of MediaWiki in community sites, the potential attack surface is broad.

Generated by OpenCVE AI on September 20, 2026 at 15:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the EmbedVideo extension to version 4.1.0 or newer, which removes the unsanitized exception handling path.
  • If upgrading is not immediately possible, temporarily disable the #ev and evl parser functions or block the error output by configuring the extension to suppress exception messages for unknown services.
  • Restrict page edit permissions audit on pages that already include malformed service names to locate and neutralize any embedded payloads.

Generated by OpenCVE AI on September 20, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c29q-5xm7-5p62 StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized service name in exception text
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Starcitizenwiki
Starcitizenwiki mediawiki-extensions-embedvideo
Vendors & Products Starcitizenwiki
Starcitizenwiki mediawiki-extensions-embedvideo

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedServiceFactory::newFromName in includes/EmbedService/EmbedServiceFactory.php interpolates an attacker-controlled unknown service name into exception text, and includes/EmbedVideo.php returns that text as HTML through the isHtml output path without neutralization. Both the #ev parser function and the evl parser form can reach this error path. A user able to edit a wiki page can inject stored HTML or JavaScript into the error output, causing code to execute in the wiki origin for visitors who render the page. This issue is fixed in version 4.1.0.
Title EmbedVideo Extension: Stored XSS via unsanitized service name in exception text
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Starcitizenwiki Mediawiki-extensions-embedvideo
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T19:45:29.252Z

Reserved: 2026-06-17T00:13:10.650Z

Link: CVE-2026-55690

cve-icon Vulnrichment

Updated: 2026-09-15T19:07:19.714Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T17:17:22.040

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-55690

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')