Description
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/EmbedService/EmbedHtmlFormatter.php passes the user-supplied class value directly to sprintf while constructing a figure element. A quote in the class value can terminate the class attribute and inject arbitrary HTML attributes or markup into the rendered page. A user able to edit a wiki page can store JavaScript that executes for visitors who render the affected content. This issue is fixed in version 4.1.0.
Published: 2026-09-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting allowing arbitrary client‑side script execution
Action: Patch Now
AI Analysis

Impact

The EmbedVideo extension processes a user‑supplied class value without sanitization, inserting it directly into the figure element’s class attribute. This flaw permits a malicious user to inject a quote that terminates the class string and appends arbitrary HTML attributes or JavaScript. When a page containing the vulnerable tag is rendered, the injected script executes in the user’s browser, potentially enabling cookie theft or session hijacking.

Affected Systems

The vulnerability exists in the StarCitizenWiki mediawiki-extensions-EmbedVideo extension in all releases before version 4.1.0. Any MediaWiki site that has not updated past this release is affected and can accept stored malicious markup via its parser functions or tags.

Risk and Exploitability

The CVSS score of 8.6 classifies the flaw as high severity. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploit as of now. However, the user with edit rights can create or modify a page to include the vulnerable class value, resulting in persistent script injection for all anonymous and authenticated visitors alike. The impact is confined to client browsers, but it can compromise user sessions, credentials, and potentially other sensitive data exposed in the context of the wiki.

Generated by OpenCVE AI on September 20, 2026 at 15:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the EmbedVideo extension to version 4.1.0 or later, which adds proper sanitization to the class attribute and removes the XSS vector.
  • disable the EmbedVideo extension entirely or restrict its use to trusted administrators, preventing unauthenticated or low‑privilege editors from inserting dangerous markup.
  • Review existing wiki pages for embedded video tags that may contain malicious class values and replace or remove them manually as a temporary safety measure.

Generated by OpenCVE AI on September 20, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-7h5p-637f-jfr7 StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized class passed to template
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Starcitizenwiki
Starcitizenwiki mediawiki-extensions-embedvideo
Vendors & Products Starcitizenwiki
Starcitizenwiki mediawiki-extensions-embedvideo

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/EmbedService/EmbedHtmlFormatter.php passes the user-supplied class value directly to sprintf while constructing a figure element. A quote in the class value can terminate the class attribute and inject arbitrary HTML attributes or markup into the rendered page. A user able to edit a wiki page can store JavaScript that executes for visitors who render the affected content. This issue is fixed in version 4.1.0.
Title EmbedVideo Extension : Stored XSS via unsanitized class passed to template
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Starcitizenwiki Mediawiki-extensions-embedvideo
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:44:27.031Z

Reserved: 2026-06-17T00:13:10.650Z

Link: CVE-2026-55691

cve-icon Vulnrichment

Updated: 2026-09-16T15:44:00.515Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T17:17:22.187

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-55691

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')