Description
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent configuration enabled, includes/EmbedService/EmbedHtmlFormatter.php places JSON returned through includes/EmbedService/AbstractEmbedService.php into the data-mw-iframeconfig attribute without safely escaping single quotes. Attacker-controlled archiveorg identifiers and wistia or sharepoint URLs accepted by the affected service validators can cause getUrl() output to terminate the attribute and inject event-handler attributes into the generated figure element. A user able to edit a wiki page can store JavaScript that executes in the wiki origin when visitors render the page. This issue is fixed in version 4.1.0.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Immediately
AI Analysis

Impact

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to version 4.1.0, with the default $wgEmbedVideoRequireConsent configuration enabled, includes/EmbedService/EmbedHtmlFormatter.php places JSON returned through includes/EmbedService/AbstractEmbedService.php into the data‑mw‑iframeconfig attribute without safely escaping single quotes. Attacker‑controlled archiveorg identifiers and wistia or sharepoint URLs accepted by the affected service validators can cause getUrl() output to terminate the attribute and inject event‑handler attributes into the generated figure element. This vulnerability allows a user with editing rights to embed a specially crafted video URL in a MediaWiki page. A user able to edit a wiki page can store JavaScript that executes in the wiki origin when visitors render the page. The injected JavaScript is executed in the context of the wiki’s origin whenever any user views the page, permitting defacement, unauthorized data access, and potential session hijacking. This issue is fixed in version 4.1.0. The flaw represents a classic stored XSS flaw and does not provide any form of server‑side control or arbitrary code execution.

Affected Systems

The issue affects installations of the StarCitizenWiki MediaWiki extension EmbedVideo prior to version 4.1.0, with the default $wgEmbedVideoRequireConsent configuration enabled. The vulnerability is triggered when the page author supplies a malicious video URL that bypasses the service validators. If an organization uses older versions of this extension, any page that has been edited to include the malformed video link is at risk.

Risk and Exploitability

With a CVSS score of 7.5 and an EPSS score below 1 %, the vulnerability is considered moderate‑high severity but low probability of widespread exploitation. It is not listed in CISA’s KEV catalog. An attacker must first have the ability to edit a wiki page, then craft a video URL containing a malicious payload. Once stored, the payload runs in the browser of any user who views the page, thereby affecting all visitors of that page. Based on the description, the likely attack vector is client‑side social engineering combined with content modification permissions; exploitation requires no network connectivity to the attacker’s machine beyond the page load.

Generated by OpenCVE AI on September 20, 2026 at 15:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the EmbedVideo extension to version 4.1.0 or newer to apply the vendor patch.
  • Verify that the configuration variable $wgEmbedVideoRequireConsent remains enabled and that no other untrusted input sources are allowed to create figure elements containing unescaped data attributes.
  • Restrict or monitor edit permissions for pages that use video embeds, ensuring only trusted users can insert or modify #ev calls or EmbedVideo tags.

Generated by OpenCVE AI on September 20, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5c7p-g73q-rpg5 StarCitizenWiki Extension Embed Video: Stored XSS via malformed src url with $wgEmbedVideoRequireConsent enabled
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Starcitizenwiki
Starcitizenwiki mediawiki-extensions-embedvideo
Vendors & Products Starcitizenwiki
Starcitizenwiki mediawiki-extensions-embedvideo

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent configuration enabled, includes/EmbedService/EmbedHtmlFormatter.php places JSON returned through includes/EmbedService/AbstractEmbedService.php into the data-mw-iframeconfig attribute without safely escaping single quotes. Attacker-controlled archiveorg identifiers and wistia or sharepoint URLs accepted by the affected service validators can cause getUrl() output to terminate the attribute and inject event-handler attributes into the generated figure element. A user able to edit a wiki page can store JavaScript that executes in the wiki origin when visitors render the page. This issue is fixed in version 4.1.0.
Title EmbedVideo Extension: Stored XSS via malformed src url with $wgEmbedVideoRequireConsent enabled
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Starcitizenwiki Mediawiki-extensions-embedvideo
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T19:03:49.954Z

Reserved: 2026-06-17T00:13:10.650Z

Link: CVE-2026-55692

cve-icon Vulnrichment

Updated: 2026-09-15T19:03:46.829Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T17:17:22.330

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-55692

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')